- What's New
- Product Bulletin
- Service Overview
- Billing
- Getting Started
-
User Guide
-
UCS Clusters
- Overview
- Huawei Cloud Clusters
-
On-Premises Clusters
- Overview
- Service Planning for On-Premises Cluster Installation
- Registering an On-Premises Cluster
- Installing an On-Premises Cluster
- Managing an On-Premises Cluster
- Attached Clusters
- Multi-Cloud Clusters
- Single-Cluster Management
- Fleets
-
Cluster Federation
- Overview
- Enabling Cluster Federation
- Using kubectl to Connect to a Federation
- Upgrading a Federation
-
Workloads
- Workload Creation
-
Container Settings
- Setting Basic Container Information
- Setting Container Specifications
- Setting Container Lifecycle Parameters
- Setting Health Check for a Container
- Setting Environment Variables
- Configuring a Workload Upgrade Policy
- Configuring a Scheduling Policy (Affinity/Anti-affinity)
- Configuring Scheduling and Differentiation
- Managing a Workload
- ConfigMaps and Secrets
- Services and Ingresses
- MCI
- MCS
- DNS Policies
- Storage
- Namespaces
- Multi-Cluster Workload Scaling
- Adding Labels and Taints to a Cluster
- RBAC Authorization for Cluster Federations
- Image Repositories
- Permissions
-
Policy Center
- Overview
- Basic Concepts
- Enabling Policy Center
- Creating and Managing Policy Instances
- Example: Using Policy Center for Kubernetes Resource Compliance Governance
-
Policy Definition Library
- Overview
- k8spspvolumetypes
- k8spspallowedusers
- k8spspselinuxv2
- k8spspseccomp
- k8spspreadonlyrootfilesystem
- k8spspprocmount
- k8spspprivilegedcontainer
- k8spsphostnetworkingports
- k8spsphostnamespace
- k8spsphostfilesystem
- k8spspfsgroup
- k8spspforbiddensysctls
- k8spspflexvolumes
- k8spspcapabilities
- k8spspapparmor
- k8spspallowprivilegeescalationcontainer
- k8srequiredprobes
- k8srequiredlabels
- k8srequiredannotations
- k8sreplicalimits
- noupdateserviceaccount
- k8simagedigests
- k8sexternalips
- k8sdisallowedtags
- k8sdisallowanonymous
- k8srequiredresources
- k8scontainerratios
- k8scontainerrequests
- k8scontainerlimits
- k8sblockwildcardingress
- k8sblocknodeport
- k8sblockloadbalancer
- k8sblockendpointeditdefaultrole
- k8spspautomountserviceaccounttokenpod
- k8sallowedrepos
- Configuration Management
- Traffic Distribution
- Observability
- Container Migration
- Pipeline
- Error Codes
-
UCS Clusters
- Best Practices
-
API Reference
- Before You Start
- Calling APIs
-
API
- UCS Cluster
-
Fleet
- Adding a Cluster to a Fleet
- Removing a Cluster from a Fleet
- Registering a Fleet
- Deleting a Fleet
- Querying a Fleet
- Adding Clusters to a Fleet
- Updating Fleet Description
- Updating Permission Policies Associated with a Fleet
- Updating the Zone Associated with the Federation of a Fleet
- Obtaining the Fleet List
- Enabling Fleet Federation
- Disabling Cluster Federation
- Querying Federation Enabling Progress
- Creating a Federation Connection and Downloading kubeconfig
- Creating a Federation Connection
- Downloading Federation kubeconfig
- Permissions Management
- Using the Karmada API
- Appendix
-
FAQs
- About UCS
-
Billing
- How Is UCS Billed?
- What Status of a Cluster Will Incur UCS Charges?
- Why Am I Still Being Billed After I Purchase a Resource Package?
- How Do I Change the Billing Mode of a Cluster from Pay-per-Use to Yearly/Monthly?
- What Types of Invoices Are There?
- Can I Unsubscribe from or Modify a Resource Package?
-
Permissions
- How Do I Configure Access Permissions for Each Function of the UCS Console?
- What Can I Do If an IAM User Cannot Obtain Cluster or Fleet Information After Logging In to UCS?
- How Do I Restore ucs_admin_trust I Deleted or Modified?
- What Can I Do If I Cannot Associate the Permission Policy with a Fleet or Cluster?
- How Do I Clear RBAC Resources After a Cluster Is Unregistered?
- Policy Center
-
Fleets
- What Can I Do If Cluster Federation Verification Fails to Be Enabled for a Fleet?
- What Can I Do If an Abnormal, Federated Cluster Fails to Be Removed from the Fleet?
- What Can I Do If an Nginx Ingress Is in the Unready State After Being Deployed?
- What Can I Do If "Error from server (Forbidden)" Is Displayed When I Run the kubectl Command?
- Huawei Cloud Clusters
- Attached Clusters
-
On-Premises Clusters
- What Can I Do If an On-Premises Cluster Fails to Be Connected?
- How Do I Manually Clear Nodes of an On-Premises Cluster?
- How Do I Downgrade a cgroup?
- What Can I Do If the VM SSH Connection Times Out?
- How Do I Expand the Disk Capacity of the CIA Add-on in an On-Premises Cluster?
- What Can I Do If the Cluster Console Is Unavailable After the Master Node Is Shut Down?
- What Can I Do If a Node Is Not Ready After Its Scale-Out?
- How Do I Update the CA/TLS Certificate of an On-Premises Cluster?
- What Can I Do If an On-Premises Cluster Fails to Be Installed?
- Multi-Cloud Clusters
-
Cluster Federation
- What Can I Do If the Pre-upgrade Check of the Cluster Federation Fails?
- What Can I Do If a Cluster Fails to Be Added to a Federation?
- What Can I Do If Status Verification Fails When Clusters Are Added to a Federation?
- What Can I Do If an HPA Created on the Cluster Federation Management Plane Fails to Be Distributed to Member Clusters?
- What Can I Do If an MCI Object Fails to Be Created?
- What Can I Do If I Fail to Access a Service Through MCI?
- What Can I Do If an MCS Object Fails to Be Created?
- What Can I Do If an MCS or MCI Instance Fails to Be Deleted?
- Traffic Distribution
- Container Intelligent Analysis
- General Reference
Copied.
Using a VPC Peering Connection to Connect CCE Clusters
Application Scenarios
Before creating an MCS object, ensure connectivity of both inter-cluster nodes and containers. You can create a VPC peering connection to connect CCE clusters across VPCs.
This section describes how you can create a VPC peering connection for connectivity of both inter-cluster nodes and containers.
Configuring Cluster Network Types
CCE Cluster Type |
Network Type |
Support Underlay Network |
---|---|---|
CCE clusters |
Container tunnel network |
No |
VPC network |
Yes |
|
CCE Turbo clusters |
Cloud native network 2.0 |
Yes |
Creating a VPC Peering Connection
- Go to the VPC peering connection list page.
- In the upper right corner of the page, click Create VPC Peering Connection. In the displayed dialog box, configure parameters as prompted. For details about the parameters, see Table 2.
Figure 1 Creating a VPC peering connection
Table 2 Parameters for creating a VPC peering connection Parameter
Mandatory
Description
VPC Peering Connection Name
Yes
Name of the VPC peering connection.
The name can contain a maximum of 64 characters, including letters, digits, hyphens (-), and underscores (_).
Local VPC
Yes
VPC of the local cluster. Select one from the drop-down list.
Local VPC CIDR Block
Yes
CIDR block of the local VPC.
Account
Yes
Select My account or Another account. In this example, My account is selected.
- My account: The local and peer VPCs are from the same account.
- Another account: The local and peer VPCs are from different accounts.
Peer Project
Yes
The system fills in the corresponding project by default when Account is set to My account.
For example, if two VPCs (VPC-A and VPC-B) are in account A in region A, the system fills in the corresponding project of account A in region A by default.
Peer VPC
Yes
VPC of the peer cluster. Select one from the drop-down list.
Peer VPC CIDR Block
Yes
CIDR block of the peer VPC.
The local and peer VPCs cannot have identical or overlapping CIDR blocks. Otherwise, the routes added for the VPC peering connection may not take effect.
Description
No
Description of the connection. Enter up to 255 characters. Angle brackets (< or >) are not allowed.
- Click the VPC peering connection name. On the displayed page, click Add Route.
As shown in Figure 2, you need to configure VPC CIDR blocks for local and peer clusters. For details, see Table 3.
Table 3 Route parameters Parameter
Mandatory
Description
Destination
Yes
Enter the VPC CIDR block for the peer cluster.
To query this CIDR block:- Log in to the VPC console.
- In the navigation pane, choose Virtual Private Cloud > My VPCs. On the displayed page, locate the peer VPC and copy its IPv4 CIDR block.
Figure 3 Querying the VPC CIDR block of the peer clusterDestination
Yes
Enter the VPC CIDR block for the local cluster.
CAUTION:The destination of each route must be unique.
Description
No
Supplementary information about the route.
Enter up to 255 characters. Angle brackets (< or >) are not allowed.
- On the VPC peering connection details page, click Add Route.
As shown in Figure 4, you need to configure container CIDR blocks for local and peer clusters. For details, see Table 4.
Table 4 Route parameters Parameter
Mandatory
Description
Destination
Yes
Enter the container CIDR block of the peer cluster.
To query this CIDR block:- Log in to the CCE console.
- Click the name of the target cluster to access the cluster console. In the Networking Configuration area, hover over the name of Default Pod Subnet and copy the IPv4 CIDR block.
CAUTION:
If there are multiple CIDR blocks, create a route for each CIDR block for communication between containers.
Figure 5 Querying the container CIDR block of the peer clusterDestination
Yes
Enter the container CIDR block of the local cluster.
CAUTION:The destination of each route must be unique.
Description
No
Supplementary information about the route.
Enter up to 255 characters. Angle brackets (< or >) are not allowed.
Changing a Security Group
Change the security group for the node in the local cluster to allow the node in the peer cluster to access over the local container port in the inbound rule.
Verifying Connectivity Between Clusters
- Log in to the node in the local cluster and run the following command to verify the communication between the nodes in the local and peer clusters:
ping IP address of the node in the peer cluster
If the ping succeeds, the cluster connectivity is normal.
- Access the container in the local cluster and run the following command to verify the communication between the containers in the local and peer clusters:
curl IP address of the pod in the peer cluster
If the access succeeds, the container connectivity is normal.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot