Huawei Cloud Stack 8.5.0 Solution Description 04

Cloud Services and Common Components

Cloud Services and Common Components

Huawei Cloud Stack provides a rich store of cloud services and common components that provide basic functions for these cloud services.

Table 1-1 Compute services

Cloud Service/Common Component

Description

ECS

An Elastic Cloud Server (ECS) is a compute server that consists of vCPUs, memory, images, and Elastic Volume Service (EVS) disks, allowing on-demand allocation and elastic scaling. It is used together with cloud services such as Virtual Private Cloud (VPC), Network ACL, and Cloud Server Backup Service (CSBS) to construct an efficient, reliable, and secure computing environment, ensuring stable and continuous running of services.

BMS

Bare Metal Server (BMS) is a way of provisioning dedicated physical servers for tenants. It provides remarkable computing performance and stability for running key applications. The BMS service can be used in conjunction with other cloud services, such as Virtual Private Cloud (VPC), so that you can enjoy consistent and stable performance of server hosting as well as the high scalability of cloud resources.

IMS

In Image Management Service (IMS), an image is an Elastic Cloud Server (ECS) template containing mandatory software, such as the operating system (OS). The template may also contain application software, such as database software, and proprietary software. Images can be divided into public, private, and shared images. You can use a public, private, or shared image to create ECSs. You can also create a private image from an existing ECS or an external image file.

AS

Auto Scaling (AS) is a service that automatically adjusts resources based on service requirements and configured AS policies. You can specify AS configurations and policies based on service requirements. These configurations and policies free you from repeated adjustment of resources in response to service changes and demand spikes, helping reduce resources and labor costs required.

Table 1-2 Storage services

Cloud Service/Common Component

Description

EVS

Elastic Volume Service (EVS) is a virtual block storage service, which provides block storage space for Elastic Cloud Servers (ECSs) and Bare Metal Servers (BMSs). Users can create EVS disks on the console and attach them to ECSs. The method for using EVS disks is the same as that for using hard disks on physical servers. Additionally, EVS disks have higher data reliability and I/O throughput and are easier to use. EVS disks are suitable for file systems, databases, or system software or applications that require block storage devices.

SFS

Scalable File Service (SFS) provides fully-hosted shared file storage for ECSs. In compliance with the Network File System (NFS and CIFS) protocol, SFS can support storage of PB-level files. With the scalable performance, SFS can seamlessly handle data-intensive and high-bandwidth applications.

SFS-DJ, that is, OceanStor DJ (Manila), functions as the SFS server and receives requests from the SFS Console.

OBS 3.0

Object Storage Service (OBS) is a cloud storage service optimized for storing massive amounts of data. It provides unlimited, secure, and highly reliable storage capabilities. On OBS, you can easily perform storage management operations, such as bucket creation, modification, and deletion, as well as object upload, download, and deletion.

OBS provides users with unlimited storage capacity, stores files in any format, and caters to the needs of common users, websites, enterprises, and developers. Neither the entire OBS system nor any single bucket has limitations on storage capacity or the number of objects/files that can be stored. OBS supports APIs over Hypertext Transfer Protocol (HTTP) and Hypertext Transfer Protocol Secure (HTTPS). You can use OBS Console or OBS clients to access and manage data stored in OBS anytime, anywhere. With OBS-provided APIs, you can easily manage data stored in OBS and develop upper-layer service applications.

OBS can be deployed in multiple regions, delivering flexible expansion and enhanced reliability. You can deploy OBS in specific regions for faster access.

SFS Turbo

Scalable File Service Turbo (SFS Turbo) provides scalable, high-performance shared file storage (NAS) for shared file access from ECSs, BMSs, Cloud Container Engine (CCE) containers, and Cloud Container Instance (CCI) containers.

Table 1-3 Network services

Cloud Service/Common Component

Description

VPC

Virtual Private Cloud (VPC) enables you to provision logically isolated, configurable, and manageable virtual networks for ECSs, improving the security of resources in the system and simplifying network deployment.

You can select IP address ranges, create subnets, customize security groups, and configure route tables and gateways in a VPC, which enables you to manage and configure your network conveniently and modify your network securely and rapidly. You can also customize access rules and firewalls to control instance access within a security group and across different security groups to enhance security of instances in the subnet.

Source Network Address Translation (SNAT) maps the private IP addresses of a subnet in a VPC to a public IP address, thereby allowing the cloud servers in the subnet to access the Internet.

EIP

Elastic IP (EIP) is an IP address that can be used to access services on the cloud platform through a network other than the cloud platform. An EIP is a static public IP address. EIPs can be bound to or unbound from ECSs, BMSs, virtual IP addresses, or elastic load balancers.

EIP-QoS is a feature used to limit the external network traffic rate for EIP. This feature enables you to adjust the EIP bandwidth for users on ManageOne Operation Portal.

ELB

Elastic Load Balance (ELB) is a service that automatically distributes incoming traffic across multiple backend Elastic Cloud Servers (ECSs) based on predefined forwarding policies. It improves the fault tolerance and expands service capabilities of your applications. ELB also eliminates single points of failure (SPOFs) and improves system availability.

Network ACL

A network access control list (ACL) is a security service for VPCs. It controls access to VPCs or subnets, supports blacklist and whitelist policies (that is, permit and deny policies), and determines whether data packets can flow into or out of VPCs or subnets based on the inbound and outbound ACL rules associated with the VPCs or subnets.

VPN

Virtual Private Network (VPN) establishes an encrypted communications tunnel between a user and a Virtual Private Cloud (VPC). With VPN, you can connect to a VPC and access service resources in it.

VPN-QoS is a feature used to limit the external network traffic rate for VPN. This feature enables you to adjust the VPN bandwidth for users on ManageOne Operation Portal.

Direct Connect

Direct Connect is a dedicated connection channel for high-speed, low-latency, and stable security between a local data center and a VPC. With Direct Connect, you can use a dedicated network connection to connect your network, data center, and colocation environment to VPCs to enjoy a high-performance, low-latency, and secure network.

VPC Endpoint

VPC Endpoint (VPCEP) is a cloud service that extends VPC capabilities. It provides secure and private channels to connect VPCs to endpoint services, providing powerful and flexible networking without having to use EIPs.

CC

Cloud Connect (CC) allows you to quickly build high-speed, high-quality, and stable networks between Virtual Private Clouds (VPCs) across regions.

With CC, you can load network instances in different regions to a cloud connection to enable communication between private networks. The network instances can be VPCs in the same region or authorized VPCs in different regions.

CloudDNS

Cloud Domain Name Service (CloudDNS) translates domain names like www.example.com into IP addresses like 192.168.2.2 used for servers to connect to each other. This allows you to visit websites or web applications by simply using domain names.

ENS

Enterprise Networking Service (ENS) provides high-speed connectivity and unified security policies across resource pools and clouds. It is suitable for mixed environments having multiple regions, platforms, types of compute resources, and application architectures. ENS can interconnect resources across clouds and resource pools through IP addresses and can also interconnect applications across clusters, resource pools, and clouds through services.

Table 1-4 Security services

Cloud Service/Common Component

Description

DBAS

Database Audit Service (DBAS) provides the database audit function in out-of-path pattern. It records user access to the database in real time, generates fine-grained audit reports, and sends real-time alarms for risky operations and attacks. In addition, DBAS generates compliance reports that meet data security standards to locate internal violations and improper operations, ensuring data asset security.

DEW

  • Key Management Service (KMS) is a secure, reliable, and easy-to-use service that helps users centrally manage and protect their Customer Master Keys (CMKs) and Data Encryption Keys (DEKs).
  • Data Encryption Workshop (DEW) uses Cloud-hosted Hardware Security Module (Cloud HSMs) that are certified by China OSCCA to build password service resource pools and centrally schedule and manage the password resources. DEW provides users with a Virtual Security Module (VSM) on demand, which connects to applications to implement security functions such as data encryption and decryption, signature verification, key creation, and secure key storage.
  • Cloud Secret Management Service (CSMS) is a secure, reliable, and easy-to-use credential hosting service.

    You and your applications can use CSMS to create, retrieve, update, and delete credentials in a unified manner throughout the credential lifecycle. CSMS can help you eliminate risks incurred by hardcoding, plaintext configuration, and permission abuse.

  • Cloud Certificate Manager (CCM) is a cloud service that provides one-stop lifecycle management of digital certificates. CCM includes the SSL Certificate Manager (SCM) and Private Certificate Authority (PCA) services.

WAF

Web Application Firewall (WAF) keeps web services stable and secure. It examines all HTTP and HTTPS requests to detect and block the following attacks: Structured Query Language (SQL) injection, cross-site scripting (XSS), web shells, command and code injections, file inclusion, sensitive file access, third-party vulnerability exploits, Challenge Collapsar (CC) attacks, malicious crawlers, and cross-site request forgery (CSRF).

HSS

Host Security Service (HSS) is designed to protect server workloads in hybrid clouds and multi-cloud data centers. It provides host security functions, Container Guard Service (CGS), and Web Tamper Protection (WTP).

CFWforHCS

Cloud Firewall 2.0 (Cloud Firewall for HCS, CFWforHCS) is a next-generation cloud-native firewall. It protects Internet and VPC borders on the cloud by real-time intrusion detection and prevention, global unified access control, full traffic analysis, log audit, and tracing. CFW employs AI for intelligent defense, and can be elastically scaled to meet changing business needs, helping you easily handle security threats.

CBH

Cloud Bastion Host (CBH) is a unified security management and control platform. It provides accounting, authorization, authentication, and auditing (AAAA) management services that enable you to centrally manage cloud computing resources.

A CBH system has various functional modules, such as department, user, resource, policy, operation, and audit modules. It integrates functions such as single sign-on (SSO), unified asset management, multi-terminal access protocols, file transfer, and session collaboration. With the unified O&M login portal, protocol-based forward proxy, and remote access isolation technologies, CBH enables centralized, simplified, secure management and maintenance auditing for cloud resources such as servers, cloud hosts, databases, and application systems.

SecMaster

SecMaster is a next-generation cloud native security operations platform. It enables integrated and automatic security operations through cloud asset management, security posture management, security information and event management, security orchestration and automatic response, cloud security overview, simplified cloud security configuration, configurable defense policies, and intelligent and fast threat detection and response.

PBH

Platform Bastion Host (PBH) is mainly used in remote O&M scenarios. PBH is deployed on management nodes as the only entrance for O&M of hardware and software in management zones. In addition, PBH provides O&M account authorization and operation auditing to ensure that all O&M operations are auditable and traceable.

PBH is deployed among the IaaS services in Huawei Cloud Stack. Its functions are similar to those of CBH.

NDR

Network Detection and Response (NDR) is a security platform that protects Layer 4 to Layer 7 network traffic. It was developed based on Huawei's years of attack defense experience, combined with AI and big data analytics technologies. It detects, captures, decodes, and audits enterprise network traffic in real time to identify security risks and threats.

PHSS

Platform Host Security Service (PHSS), formerly called Compute Security Platform (CSP), reviews server assets, and scans for and reports intrusions, vulnerabilities (such as VM escape), unsafe settings, suspicious programs, and file or website content that has been tampered with. PHSS helps enterprises manage security of physical and virtual servers on the management planes of their cloud platforms, detect intrusions in real time, and meet compliance requirements.

PHSS is deployed among the IaaS services in Huawei Cloud Stack. Its functions are similar to those of HSS.

DSC

Data Security Center (DSC) is a latest-generation cloud data security management platform that protects your data assets by leveraging its data protection capabilities such as data classification, risk identification, data masking, and watermark-based source tracking. Asset Map gives you an insight into the security status of each stage in data security lifecycle and provides constant visibility of the security status of your data assets.

PWAF

Platform Web Application Firewall (PWAF) keeps web services stable and secure. It examines all HTTP and HTTPS requests to detect and block the following attacks: Structured Query Language (SQL) injection, cross-site scripting (XSS), web shells, command and code injections, file inclusion, sensitive file access, third-party vulnerability exploits, Challenge Collapsar (CC) attacks, malicious crawlers, and cross-site request forgery (CSRF).

FBUS

Fusion KnowledgeBase Upgrade Service is a unified platform that manages feature databases of security services. FBUS uses a unified management solution to provide one-click upgrade and rollback for services depending on feature databases, improving feature database upgrade efficiency.

Table 1-5 DR and backup services

Cloud Service/Common Component

Description

CSBS

Cloud Server Backup Service (CSBS). When the CSBS service is interconnected with the OceanProtect Appliance, the cloud full-stack backup service is installed. When the CSBS service is interconnected with eBackup, the cloud server backup service is installed.

In Huawei Cloud Stack 8.5.0, the OceanProtect can be added when eBackup has been installed.

In Huawei Cloud Stack 8.5.0 and later versions, eBackup does not support new installation and capacity expansion. If you need to view the O&M and usage guide related information about the eBackup service, search for Huawei Cloud Stack 8.3.1 at the enterprise or carrier website to obtain relevant documentation. Enterprise users: Click here. Carrier users: Click here.

  • Server backup enables you to create a backup for your ECS or BMS (including its flavor, system disks, and data disks) and restore service data of the ECS or BMS using the backup data, guaranteeing data security and consistency.

    The following components are used:

    • The CSBS Karbor node functions as the CSBS backend which receives requests from the CSBS Console and invokes the eBackup Server&Proxy components.
    • eBackup Server&Proxy functions as the CSBS backend which backs up data from the production storage to the backup storage.
  • The cloud full-stack backup service provides full-stack service protection capabilities in the cloud. It protects advanced services such as native storage data, DWS, and MRS in the cloud, as well as 40+ applications such as self-built databases, files, and virtualization, providing customers with comprehensive, secure, highly reliable, and cost-effective service protection capabilities.

    The components of cloud full-stack backup are as follows:

    • CSBS Console: Users can apply for cloud full-stack backup on CSBS Console to back up and restore applications on servers.
    • The CSBS Karbor node manages quotas, generates and reports call detail records (CDRs), and provides APIs for interconnecting with the cloud management layer.
    • OceanProtect provides the backup and restoration function of cloud full-stack backup and serves as the backup storage for storing copies.

CSDR

Cloud Server Disaster Recovery (CSDR) provides remote disaster recovery protection for cloud servers. If a production center fails during a disaster, protected cloud servers can be restored in the remote DR center.

CSDR supports the following protection types:

  • When the protection type is CSDR, remote DR protection can be provided for ECSs and BMSs. If the production center fails in a disaster, the protected ECSs and BMSs can be recovered in the remote DR center.
  • When the protection type is VHA+CSDR, no data is lost and services are not interrupted if a single storage device in the production center fails. If the production center fails in a disaster, the protected ECSs and BMSs can be recovered in the remote DR center.
  • When the protection type is CSHA+CSDR and the production center is faulty, services can be automatically or manually switched to the intra-city DR center to recover the protected ECSs without data loss. If the production center and intra-city DR center fail in a disaster, the protected ECSs can be recovered in the remote DR center.

eReplication functions as the CSDR backend which receives requests from the CSDR Console.

CSHA

Cloud Server High Availability (CSHA) provides cross-DC HA protection for ECSs within one city. When the production center is faulty, services on the protected ECS can be automatically or manually switched to the DR center.

eReplication functions as the CSHA backend which receives requests from the CSHA Console.

VHA

Volume High Availability (VHA) service provides local storage-based active-active protection for EVS disks on ECSs. When a storage device is faulty, no data is lost and services are not interrupted.

eReplication functions as the VHA backend which receives requests from the VHA console.

Table 1-6 Container services

Cloud Service/Common Component

Description

CCE

Cloud Container Engine (CCE) is a highly scalable, high-performance, enterprise-class Kubernetes service for you to run Docker containers and applications. With CCE, you can easily deploy, manage, and scale containerized applications in the cloud.

SWR

SoftWare Repository for Container (SWR) allows you to easily manage the full lifecycle of container images and facilitates secure deployment of images for your applications. You can upload, download, and manage container images through the SWR console, SWR APIs, or community CLI.

Table 1-7 Application services

Cloud Service/Common Component

Description

SMN

Simple Message Notification (SMN) is a reliable, flexible, and large-scale message notification service. It is designed to provide one-to-multiple message subscription and notification over a variety of protocols. It significantly reduces system coupling and pushes messages to specified subscription endpoints.

ROMA Connect

ROMA Connect is a full-stack application & data integration platform. It focuses on application and data connections and applies to multiple common scenarios of enterprises. ROMA Connect provides lightweight message, data, API, device, and model integration to simplify cloud transformation for enterprises and support cross-regional integration for cloud and on-premises applications.

DCS

Distributed Cache Service (DCS) is an online, distributed, in-memory cache service compatible with Redis. It is reliable, scalable, usable out of the box, and easy to manage, meeting your requirements for high read/write performance and fast data access.

APM

Application Performance Management (APM) monitors and manages the performance of cloud applications in real time. APM analyzes the performance of distributed applications, helping O&M personnel quickly locate and resolve faults and performance bottlenecks.

AOM

Application Operations Management (AOM) is a one-stop, multidimensional O&M management platform for cloud applications. It monitors applications and related cloud resources in real time, analyzes application health status, and provides flexible data visualization functions. It helps you detect faults in a timely manner and monitor running status of applications, services, and other resources in real time.

LTS

Log Tank Service (LTS) collects log data from hosts and cloud services. By processing massive amounts of logs efficiently, securely, and in real time, LTS provides useful insights for you to optimize the availability and performance of cloud services and applications. It also helps you efficiently perform real-time decision-making, device O&M, and service trend analysis.

ServiceStage

ServiceStage is an application management and O&M platform that lets you deploy, roll out, monitor, and maintain applications all in one place. It supports technology stacks such as Java, PHP, Python, Node.js, Docker, Tomcat, and TongWeb, and supports microservice applications such as Dubbo, Apache ServiceComb Java Chassis (Java chassis) and Spring Cloud, making it easier to migrate enterprise applications to the cloud.

Astro Zero

Astro Zero is a low-code development platform that enables visualized development and end-to-end deployment in all scenarios. It helps you quickly build industry and large-scale enterprise applications, accumulate and reuse industry assets, and accelerate digitalization.

MAS

Multi-Site High Availability Service (MAS) is derived from Huawei consumer multi-site application high availability (HA) solution. To recover services quickly and improve service continuity, MAS provides E2E service failover and DR drill capabilities covering the traffic ingress, data, and application layer.

DMS

Distributed Message Service (DMS) is a message queuing service compatible with open-source Kafka and RocketMQ, providing instances with exclusive compute, storage, and bandwidth resources.

FunctionGraph

FunctionGraph is an event-driven function hosting and computing service. With FunctionGraph, you only need to write service function codes and set the conditions. You do not need to configure or manage infrastructure like servers. FunctionGraph runs your codes with high scalability and reliability and no maintenance. You pay only for what you use and you are not charged when your code is not running.

Table 1-8 CodeArts services

Cloud Service/Common Component

Description

CodeArts Req

It provides R&D teams with easy and efficient collaboration services. With IPD (IPD value-added feature and capacity expansion), agile Scrum, and lean Kanban projects, and Knowledge, you can manage multiple projects and requirements, track bugs, manage project files, analyze statistics, and manage person-hours.

CodeArts Repo

It provides software developers with Git-based online code hosting services. It is a cloud code repository that supports security control, member and permission management, branch protection and merging, online editing, and statistics.

CodeArts Check

It is a cloud-based management service that checks code quality. Developers can easily perform static code and security checks in multiple languages and obtain comprehensive quality reports. It also provides suggestions on fixing code defects and trend analysis, effectively controlling quality and reducing costs.

CodeArts Build

It provides an easy-to-use, cloud-based build platform that supports multiple programming languages, helping you achieve continuous delivery with higher efficiency. With CodeArts Build, you can create, configure, and run build tasks in a few clicks. It automates code retrieval, build, and packaging, as well as real-time status monitoring.

CodeArts Deploy

It provides visualized, one-click deployment. It supports deployment on VMs or containers by using Tomcat, Spring Boot, and other templates or by flexibly orchestrating atomic actions. It also supports parallel deployment and seamless integration with CodeArts Pipeline, providing standard deployment environments and implementing automatic deployment.

CodeArts TestPlan

It provides one-stop automatic test factory solution, covering test case management, test plan management, test design, manual tests, automatic API testing, and EchoTest. It streamlines the entire test process, including the test design, plan, cases, execution, and reports, and provides defect reporting and quality dashboards to evaluate product quality from multiple dimensions. CodeArts TestPlan helps you efficiently manage test activities and deliver high-quality products.

CodeArts Artifact

It is designed for software release and management. Its secure software repositories allow you to manage software packages and their metadata, download release packages, and release software, achieving continuous delivery.

CodeArts Pipeline

It provides visualized continuous integration and continuous delivery (CI/CD) software pipelines that can be orchestrated. It helps enterprises quickly realize continuous delivery and efficient automation, shortens the time to market (TTM) of applications, and improves R&D efficiency.

CodeArts Wiki

It provides a simple and powerful editor, with which you can collaborate with others in editing online documents, upload and download documents, and manage documents.

Table 1-9 Enterprise Intelligence (EI) services

Cloud Service/Common Component

Description

MRS

MapReduce (MRS) is a cloud-based data processing and analysis service that is reliable, scalable, easy to manage, and immediately ready for use.

MRS builds a reliable, secure, and easy-to-use platform that provides storage and analysis capabilities to process massive amounts of data. You can apply for and use hosted components like Hadoop, Spark2x, HBase, and Hive to quickly create clusters on a host and provide batch storage and computing capabilities for massive data that has low requirements on real-time processing. You can delete the clusters as soon as completing data storage and computing.

GaussDB(DWS)

GaussDB (DWS) is an online data processing database that uses the cloud infrastructure to provide scalable, fully-managed, and out-of-the-box analytic database service. It is a native cloud service based on Huawei converged data warehouse GaussDB, and is fully compatible with ANSI SQL 99 and SQL 2003 standards, as well as the PostgreSQL and Oracle database ecosystems. GaussDB (DWS) provides competitive solutions for PB-level big data analytics in various industries.

DataArts Studio

DataArts Studio is a one-stop data operations platform that drives digital transformation. It allows you to perform many operations, such as integrating and developing data, designing data standards, controlling data quality, managing data assets, creating data services, and ensuring data security. Incorporating big data storage, computing, and analytical engines, DataArts Studio can also be used to construct industry knowledge bases and help your enterprise build an intelligent end-to-end data system. This system can eliminate data silos, unify data standards, accelerate data monetization, and accelerate your enterprise's digital transformation.

TICS

Trusted Intelligent Computing Service (TICS) breaks down data silos and performs multi-party data analysis and federated computing within and between industries with data privacy protected. TICS uses technologies such as Arm TrustZone, secure multi-party computing (MPC), and blockchain to protect and audit data during storage, transmission, and computing. TICS promotes cross-industry trusted data convergence and collaboration.

ModelArts

ModelArts provides a one-stop platform for you to manage jobs and resources. With model training, model management, and model deployment, ModelArts allows you to train and deploy your models quickly. ModelArts underlying supports various heterogeneous compute resources, enabling you to flexibly use the resources without having to consider the underlying technologies. This simplifies your AI development.

GES

Graph Engine Service (GES) uses the self-developed EYWA kernel to facilitate querying and analysis of graph-structure data based on various relationships. It is specifically suited for scenarios requiring analysis of rich relationship data, including social relationship analysis, marketing recommendations, public opinions and social listening, information communication, and anti-fraud.

AI Cortex

  • AI Video Service (AIVS) leverages ModelArts inference and mature video and image gateways to upgrade traditional video surveillance to image parsing. It is an intelligent video and image data analysis platform that enables video data ingestion, algorithm management, training management, analysis job management, resource management, and event alarm reporting.
  • GeoGenius is a series of smart city solutions powered by a combination of cutting-edge technologies such as cloud computing, big data, and AI and tailored to scenario-specific needs. GeoGenius ingests and analyzes huge amounts of data collected from a modern city and builds a spatiotemporal data foundation for all-domain sensing, perception, analysis, and decision-making support. By working with partners in a wide range of areas, Huawei is committed to building GeoGenius into an intelligent platform that helps the government and enterprises accelerate digital transformation with intelligent data services and AI applications.

AI Kits

AI Kits is a system that integrates Speech Interaction Service (SIS), Optical Character Recognition (OCR), and trouble of moving freight car detection system (TFDS).

AI Kits optimizes and integrates ICT technologies and converged data to enable collaboration and agile innovation of services such as speech interaction, certificate recognition, and TFDS, and to build a digital foundation. AI Kits supports quick development and flexible deployment of services, and agile innovation of services in a wide range of industries. It also supports collaborative optimization through ubiquitous links, streamlining the physical and digital worlds.

PanguLM

Pangu Large Models (PanguLM) is a one-stop platform provided by Huawei Cloud for large model development and application. Based on PanguLM, Huawei Cloud has been building tailored models and capability sets for a wide range of industries. The PanguLM Open Platform provides multiple large model services, supports customized development of large models, and provides a tool chain covering the entire lifecycle of large models.

eiHealth

The eiHealth platform is a professional AI R&D platform for genome analysis and drug R&D and research based on AI and big data technologies. It is a one-stop medical R&D platform that provides a large number of models, algorithms, and data resources.

Table 1-10 Database services

Cloud Service/Common Component

Description

GaussDB

GaussDB is an enterprise-grade distributed relational database from Huawei. It features Hybrid Transactional/Analytical Processing (HTAP) workloads and intra-city cross-AZ deployment with zero data loss. With a distributed architecture, GaussDB supports petabytes of storage and more than 1,000 nodes per DB instance. It is highly available, secure, and scalable and provides capabilities including quick deployment, backup, restoration, monitoring, and alarm reporting for enterprises. The openGauss community provides open-source standalone and primary/standby instances for partners and developers to build an open and prosperous database ecosystem.

DRS

Data Replication Service (DRS) is an easy-to-use, stable, and efficient cloud service for online database migration and real-time database synchronization. It simplifies the data flow between databases, significantly reducing data transmission costs. DRS enables you to quickly transfer data between databases in different scenarios.

RDS

Relational Database Service (RDS) is an online relational database service based on the cloud computing platform. It is stable, reliable, scalable, and easy to manage. You can use RDS immediately after purchasing it. RDS supports the provisioning and management of MySQL databases and has a comprehensive performance monitoring system and security protection measures. By providing a professional database management platform, RDS enables you to easily set up, operate, and scale relational databases on the cloud.

DDS

Document Database Service (DDS) is a MongoDB-compatible database service that is secure, highly available, reliable, scalable, and easy to use. It provides the one-click deployment, elastic scaling, DR, backup, restoration, monitoring, and alarm reporting functions.

Table 1-11 Management service

Cloud Service/Common Component

Description

Service Builder

Backed by open service APIs, O&M automation capabilities, and the government and enterprise process adaptation engine, Service Builder provides a unified process and a robust ecosystem for provisioning IT capabilities as services. You can quickly apply for, provision, configure, and deploy IT resources and capabilities online.

Table 1-12 IoT services

Cloud Service/Common Component

Description

IoTDA

The Internet of Things Device Access (IoTDA) service provides functions such as device fleet access, bidirectional message communication, device monitoring, device O&M, OTA upgrade, device linkage rules, and data openness. It can flexibly transfer device data to other services or message middleware. You can quickly connect devices to IoTDA and integrate your applications.

DRIS

V2X, IoT, and other smart technologies provided by Digital Road Infrastructure Service (DRIS) enable full collaboration of pedestrians, vehicles, roads, and clouds. The service enables intelligent transportation and automated driving, makes travelling safer, more efficient, and more convenient, and provides all-road sensing, all-weather road service, and full-process management and control for city managers.

IoTEdge

The IoT Edge is an OS for edge computing. It manages edge gateways and clusters, and supports the access of mass gateways and clusters.

It also supports various edge computing applications and provides key capabilities such as one-click deployment and trustworthy deployment.

Table 1-13 Enterprise application service

Cloud Service/Common Component

Description

Workspace

Huawei Cloud Workspace is a workspace service based on cloud computing. Unlike conventional PCs and VDIs, Workspace enables your organization to quickly build office environments without investing a large amount of money and spending days on deployment. Workspace supports multiple login options, allowing you to flexibly access files and use applications for mobile work.

Table 1-14 aPaaS service

Cloud Service/Common Component

Description

KooMap

KooMap provides five sub-services: satellite image generation, real-scene 3D modeling, spatiotemporal data storage and computing engine, spatiotemporal information, and visualization.

  • Satellite image generation is a process of generating image data that can be used by applications in various industries by processing original remote sensing optical satellite images.
  • Real-scene 3D modeling uses 3D reconstruction to quickly restore data collected in real scenarios to a 3D world and generate a digital foundation that supports application data in various industries.
  • Spatiotemporal data storage and computing engine is a data foundation built on the storage and computing base of Huawei Cloud Stack. It provides standard and high-quality city data models for city digital twins and smart cities as well as a basic data platform for city service collaboration and data sharing, and supports improved city governance capabilities and service levels through converged data and twin computing capabilities.
  • Visualization is a high-rendering digital twin platform dedicated to becoming a powerful tool for BIM/CIM 3D visualization in terms of data processing, scenario integration, cloud service release, data sharing, 2D/3D visualization, editing, cross-platform secondary development, and industry applications. Aimed at providing users with a complete plug-in-free, cross-platform, and cross-browser solution from raw data to final 3D presentation, visualization delivers superior performance, effect, usability, and interaction.
  • Spatiotemporal information is a basic platform for city information models used to display and manage all elements of a city's 3D space. It integrates technologies such as building information modeling (BIM), IoT, cloud computing, big data, automatic identification, and intelligent analysis, and multi-source information such as remote sensing information, multi-dimensional geographic city information, BIM of buildings and aboveground/underground facilities, and city perception information.
Table 1-15 Common components

Cloud Service/Common Component

Description

LVS

Linux Virtual Server (LVS) is a Linux server cluster system that provides level-1 load balancing for hybrid cloud common services.

Nginx

Nginx provides a reverse proxy for the cloud service console page to implement load balancing of services and data on each console node and distribute traffic. Cloud service requests are delivered by the LVS and forwarded to the Nginx. The Nginx forwards the cloud service requests to the cloud service console.

NTP

Network Time Protocol (NTP) provides time synchronization for hybrid cloud services, ManageOne, and tenant VMs.

HAProxy

HAProxy: Provides load balancing for cloud services from the console node to service node. Cloud service requests are sent from the console node to HAProxy. Then HAProxy forwards the requests to the required cloud service node.

API Gateway

API Gateway: Provides API management as well as API intranet and extranet isolation functions. When a user accesses a cloud service API, the user does not call the service API directly, but accesses the API of the service registered on API Gateway. In this way, invalid requests are shielded, preventing the internal management API from being exposed.

TaskCenter

Used to view the creation of service instances such as ECS.

DNS

Domain Name System (DNS) provides the domain name resolution service for cloud services, ManageOne, and tenant VMs.

SDR

Service Detail Record (SDR): Provides metering and charging files of each cloud service.

CCS

Cloud Configuration Service (CCS) allows users to access third-party cloud resources based on the hybrid cloud, and it provides capabilities of cross-cloud management and deployment.

DMK

Deploy Management Kit (DMK) is a unified deployment and configuration platform on which all services can be installed and upgraded.

GaussDB

GaussDB: Provides common databases for cloud services.

EulerOS

Management VMs where cloud services are deployed use EulerOS as the operating system.

Table 1-16 Cloud management

Cloud Service/Common Component

Description

ManageOne

Provides cloud service operation management and system O&M management.

ManageOne_B2B: In the B2B large-scale scenario, the tenant portal is isolated from the management portal, and the tenant portal and management portal can be accessed from the intranet and public network.

eSight

Manages servers, storage devices, and network devices in a unified manner.

FusionCare

A tool specific to O&M personnel for unified health check and FusionSphere offline log collection.

HCS ServiceLink

ServiceLink establishes a secure and easy-to-maintain connection channel between the Huawei Cloud Stack remote O&M platform and customer clouds, which provides the capability of auditing remote O&M operations, and also improves security and simplifies network configurations.

CloudNetDebug

It is an O&M tool, which helps O&M personnel capture packets automatically. CloudNetDebug integrates the probe and packet capture functions to handle various network problems that may occur in the data center. The probe function can automatically check whether the service network is interrupted and whether packet loss occurs. The packet capture function can be used to implement automatic packet capture, supporting multi-point collaborative packet capture based on service flows and single-point VM NIC packet capture and host NIC packet capture.

LogCenter

LogCenter provides unified log collection and analysis capabilities and can collect operation logs of the management and tenant portals and run logs of cloud services.

AutoOps

AutoOps: Provides full-stack O&M automation from infrastructure to service applications based on the O&M automation platform built with agile O&M. With a library of rich O&M cases, AutoOps allows flexible orchestration of O&M processes to standardize O&M scenarios. It supports scheduled and immediate execution of O&M tasks in batches and can expand to meet growing business demands. By deploying AutoOps, users can effectively reduce their labor costs and management risks while improving the O&M efficiency and customer satisfaction.

MOPortal

MOPortal: Displays introduction, advantages, solutions, and more of the supported cloud services on the hybrid cloud.

ManageOne_OCC

Operations Command Center (OCC) aims at digital operations of full-stack cloud. Analytics room provides operations data analysis and decision-making support. Duty room traces daily events and distributes problems. Work shop is responsible for data processing and production, and provides data services. The analytics room, work shop, and duty room work together to ensure stable running of cloud platform services.

Public Cloud Management

  • Cloud Federation with Huawei Cloud

    A combination of federated authentication and individual user permission settings ensures that the permissions for Huawei Cloud Stack and Huawei Cloud accounts are kept consistent, allowing Virtual Data Center (VDC) users of Huawei Cloud Stack to access the Huawei Cloud console and use its services.

Cloud Federation with Huawei Cloud Stack Management

  • Cloud Federation with Huawei Cloud Stack

    By using cloud federation, you can borrow resources from peer Huawei Cloud Stack, as well as register, provision, create, use, and manage resources of peer Huawei Cloud Stack.

  • Interconnection with Huawei Cloud Stack using APIs

    Interconnection with Huawei Cloud Stack using APIs allows you to interconnect the local Huawei Cloud Stack with the peer Huawei Cloud Stack using the peer Huawei Cloud Stack API Gateway when resources on the local Huawei Cloud Stack are insufficient so that you can quickly request and borrow resources from the peer Huawei Cloud Stack.

HCS Online Management

A combination of federated authentication and individual user permission settings ensures that the permissions for Huawei Cloud Stack and Huawei Cloud Stack Online (HCS Online) accounts are kept consistent, allowing Virtual Data Center (VDC) users of Huawei Cloud Stack to access the HCS Online console and use its services.

Table 1-17 Resource pools

Cloud Service/Common Component

Description

FusionSphere OpenStack

Based on the Huawei-developed cloud computing platform, FusionSphere is designed and optimized for enterprise cloud computing data center scenarios. It provides powerful virtualization functions and resource pool management capabilities, comprehensive cloud infrastructure components and tools, and open and standard APIs, helping customers horizontally integrate physical and virtual resources in data centers and vertically optimize service platforms.

Service OM

Provides cloud service O&M capabilities.

Management Interface Overview

Category

Interface

Description

Resource pools

FusionSphere OpenStack Web Client (CPS)

A service providing the infrastructure virtualization function and used to deploy components of OpenStack services on different hosts.

Service OM

Provides cloud service O&M capabilities.

Management domain

ManageOne Maintenance Portal

ManageOne Maintenance Portal is the only entry for ManageOne O&M management. It provides cloud service O&M management capabilities to implement end-to-end (E2E) monitoring of cloud services, including cloud service itself, tenant resources, and infrastructure (computing, storage, and network devices) that cloud services depend on. It collects and displays alarm information about the monitored objects, and provides report, large-screen, and advanced O&M data analysis capabilities based on these monitoring and alarm data. In addition, ManageOne Maintenance Portal integrates with cloud service O&M systems to integrate common configurations of multiple cloud services, implementing unified O&M.

ManageOne Operation Portal

Tenant Portal and Operation Management Portal are entries of ManageOne for tenants and operation management. They provide cloud service operation integration capabilities and integrate multiple cloud services into ManageOne. The cloud service consoles are integrated into Console Home to provide a unified portal for users to use cloud services. The service orchestration orchestrates cloud service capabilities into cloud products that can be applied for by users and displays them in the product catalog.

ManageOne Deployment Portal

Allows users to view ManageOne product information and database status.

FusionCare

FusionCare is an information collection and health check tool in the Huawei Cloud Stack solution. It supports one-click health check on node status and generates a health check report after that. It also can quickly collect logs to simplify work of the O&M personnel and facilitate fault diagnosing.

eSight

eSight is an integrated O&M management solution for enterprise data centers, campus/branch networks, unified communications, videoconferencing, and video surveillance. It provides a wide array of functions for enterprise ICT devices, including automatic configuration and deployment, visualized fault diagnosis, and intelligent capacity analysis.

CloudNetDebug

It is an O&M tool, which helps O&M personnel capture packets automatically. CloudNetDebug integrates the probe and packet capture functions to handle various network problems that may occur in the data center. The probe function can automatically check whether the service network is interrupted and whether packet loss occurs. The packet capture function can be used to implement automatic packet capture, supporting multi-point collaborative packet capture based on service flows and single-point VM NIC packet capture and host NIC packet capture.

Storage services

Huawei Distributed Block Storage Self-maintenance Platform (when Huawei Distributed Block Storage serves as service storage)

It supports O&M functions including alarm management, service monitoring, operation logging, and data configuration.

OceanStor DeviceManager (when Huawei Distributed Block Storage serves as service storage)

OceanStor DeviceManager is integrated storage management software designed for all Huawei storage systems. It can help you easily configure, manage, and maintain storage devices.

OceanStor DeviceManager (when SAN storage serves as a service storage device)

OceanStor DeviceManager is integrated storage management software designed by Huawei for a single storage system. DeviceManager can help you easily configure, manage, and maintain storage devices.

OceanStor DeviceManager (used by storage devices interconnected with SFS)

OceanStor DeviceManager is integrated storage management software designed by Huawei for a single storage system. DeviceManager can help you easily configure, manage, and maintain storage devices.

OceanStor DJ (used by the SFS backend)

The OceanStor DJ administrator GUI provides a graphical user interface for users to quickly access physical infrastructures and create resource pools and service levels.

DR and backup services

eBackup GUI

The eBackup GUI is the eBackup backup management system, which is used to perform backup and recovery operations on the protected environment.

OceanProtect GUI

The OceanProtect GUI is the OceanProtect backup management system, which is used to perform backup and restoration operations on the protected environment.

eReplication GUI

The eReplication GUI is the eReplication disaster recovery management system, which is used to perform DR protection and recovery operations on the protected objects.

Common components

API Gateway

APIG is used with industry solutions to provide high-performance, highly available, and secure API hosting services. It is an end-to-end API product that covers API running, management, analysis, and security. It decouples backend services and data from upper-layer applications, helps customers efficiently expand services, and connects customers with vendors of backend services and applications to build a developer ecosystem.

DMK

Deploy Management Kit (DMK) is a unified deployment and configuration platform on which all services can be installed and upgraded. You can quickly deploy cloud services, components, and O&M tools using the DMK platform, shorten the time required for installation.

Translation
Favorite
Download
Update Date:2025-08-12
Document ID:EDOC1100404400
Views:66217
Downloads:305
Average rating:0.0Points

Digital Signature File

digtal sigature tool