- What's New
- Product Bulletin
- Service Overview
- Billing
- Getting Started
-
User Guide
-
UCS Clusters
- Overview
- Huawei Cloud Clusters
-
On-Premises Clusters
- Overview
- Service Planning for On-Premises Cluster Installation
- Registering an On-Premises Cluster
- Installing an On-Premises Cluster
- Managing an On-Premises Cluster
- Attached Clusters
- Multi-Cloud Clusters
- Single-Cluster Management
- Fleets
-
Cluster Federation
- Overview
- Enabling Cluster Federation
- Using kubectl to Connect to a Federation
- Upgrading a Federation
-
Workloads
- Workload Creation
-
Container Settings
- Setting Basic Container Information
- Setting Container Specifications
- Setting Container Lifecycle Parameters
- Setting Health Check for a Container
- Setting Environment Variables
- Configuring a Workload Upgrade Policy
- Configuring a Scheduling Policy (Affinity/Anti-affinity)
- Configuring Scheduling and Differentiation
- Managing a Workload
- ConfigMaps and Secrets
- Services and Ingresses
- MCI
- MCS
- DNS Policies
- Storage
- Namespaces
- Multi-Cluster Workload Scaling
- Adding Labels and Taints to a Cluster
- RBAC Authorization for Cluster Federations
- Image Repositories
- Permissions
-
Policy Center
- Overview
- Basic Concepts
- Enabling Policy Center
- Creating and Managing Policy Instances
- Example: Using Policy Center for Kubernetes Resource Compliance Governance
-
Policy Definition Library
- Overview
- k8spspvolumetypes
- k8spspallowedusers
- k8spspselinuxv2
- k8spspseccomp
- k8spspreadonlyrootfilesystem
- k8spspprocmount
- k8spspprivilegedcontainer
- k8spsphostnetworkingports
- k8spsphostnamespace
- k8spsphostfilesystem
- k8spspfsgroup
- k8spspforbiddensysctls
- k8spspflexvolumes
- k8spspcapabilities
- k8spspapparmor
- k8spspallowprivilegeescalationcontainer
- k8srequiredprobes
- k8srequiredlabels
- k8srequiredannotations
- k8sreplicalimits
- noupdateserviceaccount
- k8simagedigests
- k8sexternalips
- k8sdisallowedtags
- k8sdisallowanonymous
- k8srequiredresources
- k8scontainerratios
- k8scontainerrequests
- k8scontainerlimits
- k8sblockwildcardingress
- k8sblocknodeport
- k8sblockloadbalancer
- k8sblockendpointeditdefaultrole
- k8spspautomountserviceaccounttokenpod
- k8sallowedrepos
- Configuration Management
- Traffic Distribution
- Observability
- Container Migration
- Pipeline
- Error Codes
-
UCS Clusters
- Best Practices
-
API Reference
- Before You Start
- Calling APIs
-
API
- UCS Cluster
-
Fleet
- Adding a Cluster to a Fleet
- Removing a Cluster from a Fleet
- Registering a Fleet
- Deleting a Fleet
- Querying a Fleet
- Adding Clusters to a Fleet
- Updating Fleet Description
- Updating Permission Policies Associated with a Fleet
- Updating the Zone Associated with the Federation of a Fleet
- Obtaining the Fleet List
- Enabling Fleet Federation
- Disabling Cluster Federation
- Querying Federation Enabling Progress
- Creating a Federation Connection and Downloading kubeconfig
- Creating a Federation Connection
- Downloading Federation kubeconfig
- Permissions Management
- Using the Karmada API
- Appendix
-
FAQs
- About UCS
-
Billing
- How Is UCS Billed?
- What Status of a Cluster Will Incur UCS Charges?
- Why Am I Still Being Billed After I Purchase a Resource Package?
- How Do I Change the Billing Mode of a Cluster from Pay-per-Use to Yearly/Monthly?
- What Types of Invoices Are There?
- Can I Unsubscribe from or Modify a Resource Package?
-
Permissions
- How Do I Configure Access Permissions for Each Function of the UCS Console?
- What Can I Do If an IAM User Cannot Obtain Cluster or Fleet Information After Logging In to UCS?
- How Do I Restore ucs_admin_trust I Deleted or Modified?
- What Can I Do If I Cannot Associate the Permission Policy with a Fleet or Cluster?
- How Do I Clear RBAC Resources After a Cluster Is Unregistered?
- Policy Center
-
Fleets
- What Can I Do If Cluster Federation Verification Fails to Be Enabled for a Fleet?
- What Can I Do If an Abnormal, Federated Cluster Fails to Be Removed from the Fleet?
- What Can I Do If an Nginx Ingress Is in the Unready State After Being Deployed?
- What Can I Do If "Error from server (Forbidden)" Is Displayed When I Run the kubectl Command?
- Huawei Cloud Clusters
- Attached Clusters
-
On-Premises Clusters
- What Can I Do If an On-Premises Cluster Fails to Be Connected?
- How Do I Manually Clear Nodes of an On-Premises Cluster?
- How Do I Downgrade a cgroup?
- What Can I Do If the VM SSH Connection Times Out?
- How Do I Expand the Disk Capacity of the CIA Add-on in an On-Premises Cluster?
- What Can I Do If the Cluster Console Is Unavailable After the Master Node Is Shut Down?
- What Can I Do If a Node Is Not Ready After Its Scale-Out?
- How Do I Update the CA/TLS Certificate of an On-Premises Cluster?
- What Can I Do If an On-Premises Cluster Fails to Be Installed?
- Multi-Cloud Clusters
-
Cluster Federation
- What Can I Do If the Pre-upgrade Check of the Cluster Federation Fails?
- What Can I Do If a Cluster Fails to Be Added to a Federation?
- What Can I Do If Status Verification Fails When Clusters Are Added to a Federation?
- What Can I Do If an HPA Created on the Cluster Federation Management Plane Fails to Be Distributed to Member Clusters?
- What Can I Do If an MCI Object Fails to Be Created?
- What Can I Do If I Fail to Access a Service Through MCI?
- What Can I Do If an MCS Object Fails to Be Created?
- What Can I Do If an MCS or MCI Instance Fails to Be Deleted?
- Traffic Distribution
- Container Intelligent Analysis
- General Reference
Copied.
Using Traffic Distribution to Implement Traffic Switchover
Application Scenarios
Distributed clusters are often deployed on the clouds or regions nearest to users for low latency. However, if a cluster in a region is faulty, service access in that region will be affected. UCS allows you to manage application traffic and data for traffic switchover, scheduling, and migration across clouds and clusters. Figure 1 shows how UCS switches traffic from a faulty cluster to ensure service continuity.
Constraints
- You have two available clusters of version 1.19 or later, and each cluster must have at least one available node.
- You have added a public zone to Huawei Cloud DNS. For details, see Routing Internet Traffic to a Website.
Setting Up the Environment
- Register clusters to UCS and configure cluster access. For details, see Registering a Cluster.
For example, register ccecluster01 and ccecluster02 to UCS and check whether they are running normally.
- Create a workload in each connected cluster.
NOTE:
In this example, container images with different tags are used to create workloads, aiming to show you more clearly how application traffic is switched.
- ccecluster01: Image tag 1.0.0 is used.
- ccecluster02: Image tag 2.0.0 is used.
- Create a LoadBalancer Service for the workloads in each cluster.
NOTE:
Only LoadBalancer Services are supported and displayed.
- Use a browser to access the IP of the LoadBalancer Service to check the deployment result.
Verifying Traffic Switchover
You have deployed applications in clusters ccecluster01 and ccecluster02 and allowed external access via LoadBalancer Services.
The following describes how to distribute application traffic to realize traffic switchover and ensure high availability.
In this example, example clusters and workloads are not limited in terms of service providers, regions, and quantity.
- Log in to the UCS console. In the navigation pane, choose Traffic Distribution.
- Click Create Traffic Policy. In the window that slides from the right, enter the domain name (use demo.example.com here).
Figure 2 Creating a traffic policy
- Add scheduling policies for the two clusters and click OK.
In this example, three scheduling policies are added to simulate cluster application deployment in different regions:
- For ccecluster01, set Line Type to Region line - Global/Asia-Pacific/Singapore.
- For ccecluster02, set Line Type to Region line - Chinese Mainland/South China/Guangdong.
- Add a default line for the domain name. For ccecluster01, set Line Type to Default. If no default line is added for the domain name, users in regions beyond the specified lines cannot access the applications.
- View the scheduling policies. Three policies have been added for demo.example.com. User traffic can access applications in the two clusters based on the configured line type and weight.
- Users in Singapore will access application 1.0.0 in ccecluster01.
- Users in Guangdong will access application 2.0.0 in ccecluster02.
- Users in other regions will access application 1.0.0 in ccecluster01 by default.
- A user in Guangdong visits demo.example.com to access the application. The response shows that the user is accessing application 2.0.0 in ccecluster02.
Figure 3 Checking the access result
- Manually stop the application in ccecluster02 and change the number of pods to 0 to simulate a fault.
Figure 4 Adjusting the pod quantity
- When a user in Guangdong accesses the application, the request is still sent to ccecluster02 and an error is returned.
In this case, click Suspend for the corresponding scheduling policy of ccecluster02 on the Traffic Distribution page to perform traffic switchover.
After that, the subsequent access requests of this user will be sent to ccecluster01 through the default line, and the access becomes normal. After the faulty cluster is recovered, you can click Enable to enable the policy again.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot