Container processing method based on edge cloud and related device
By deploying interface plugins on edge devices to maintain container identifier sets and allowing or blocking container rebuild requests, the problem of unexpected large-scale container rebuilds caused by unstable communication in edge cloud environments is solved, thus improving the service quality of edge devices.
Patent Information
- Application Number
- CN202410497548.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-19
- Publication Date
- 2025-10-24
AI Technical Summary
In edge cloud environments, unstable communication links between edge devices and the central management system can lead to unexpected user actions and large-scale container rebuilds caused by native component autonomous decisions, thus reducing the service quality of edge devices.
Deploy interface plugins on edge devices to maintain a set of container identifiers. Receive container rebuild requests from the central management system through the interface plugins, determine whether the container identifier belongs to a container with limited authorization for rebuilding, and allow or block the request to avoid unexpected large-scale container rebuilds.
This effectively avoids unintended large-scale container rebuilds and improves the service quality of edge devices.
Smart Images

Figure CN120832202A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud, in particular to a container processing method based on edge cloud and related device. BACKGROUND
[0002] The edge cloud has the characteristics of complex edge devices, complex network environment, globally distributed but locally less distributed resources, unstable communication link between the edge devices and the central management system of the cloud, and large-scale container reconstruction operation, which affects the service quality of the edge device.
[0003] In the related art, a lightweight agent is deployed on the edge device to communicate with the central management system and cache the central data of the central management system. When the communication link between the edge device and the central management system is abnormal, the lightweight agent temporarily replaces the central management system to enable the container on the edge device to run normally, so as to maintain the service quality of the edge device.
[0004] However, based on the deployment of the lightweight agent on the edge device, there are still some unexpected user operations and autonomous decisions of the native components, which cause the unexpected and large-scale container reconstruction operation on the edge device, and reduce the service quality of the edge device. SUMMARY
[0005] To solve the above technical problems, the present application provides a container processing method based on edge cloud and related device, which can avoid the unexpected and large-scale container reconstruction operation on the edge device caused by some unexpected user operations and autonomous decisions of the native components, so as to improve the service quality of the edge device.
[0006] The embodiments of the present application disclose the following technical solutions:
[0007] In one aspect, the present application provides a container processing method based on edge cloud, which is executed by an edge device, and the method comprises:
[0008] A container reconstruction request sent by a central management system is received through an interface plug-in of a container runtime; the container reconstruction request carries a first container identifier;
[0009] If the first container identifier belongs to a container identifier set, a container corresponding to the first container identifier is reconstructed according to the container reconstruction request through the interface plug-in, and a first reconstruction result is obtained; the container identifier set is used to indicate the limited authorized reconstruction container on the edge device;
[0010] If the first container identifier does not belong to the container identifier set, the container reconstruction request is intercepted through the interface plug-in.
[0011] In another aspect, an embodiment of the present application provides a container processing device based on an edge cloud, deployed on an edge device, the device comprising: a receiving unit, a reconstruction unit, and an intercepting unit;
[0012] The receiving unit is configured to receive a container reconstruction request sent by a central management system through an interface plug-in of a container runtime, wherein the container reconstruction request carries a first container identifier;
[0013] The reconstruction unit is configured to, if the first container identifier belongs to a container identifier set, perform container reconstruction on a container corresponding to the first container identifier according to the container reconstruction request through the interface plug-in, and obtain a first reconstruction result, wherein the container identifier set is used to indicate containers authorized for limited reconstruction on the edge device.
[0014] The intercepting unit is configured to, if the first container identifier does not belong to the container identifier set, intercept the container reconstruction request through the interface plug-in.
[0015] In another aspect, an embodiment of the present application provides a computer device, comprising a processor and a memory:
[0016] The memory is configured to store a computer program and transmit the computer program to the processor.
[0017] The processor is configured to execute the method according to the instructions in the computer program.
[0018] In another aspect, an embodiment of the present application provides a computer readable storage medium, configured to store a computer program, when the computer program runs on a computer device, causing the computer device to execute the method according to any one of the preceding aspects.
[0019] In another aspect, an embodiment of the present application provides a computer program product, comprising a computer program, when the computer program runs on a computer device, causing the computer device to execute the method according to any one of the preceding aspects.
[0020] It can be seen from the above technical solution that the interface plug-in of the container runtime on the edge device maintains a container identifier set to indicate the limited authorized container to be rebuilt on the edge device; based on this, when the central management system sends a container rebuild request carrying a first container identifier to the edge device, the edge device first receives the container rebuild request carrying the first container identifier sent by the central management system through the interface plug-in; then, it is judged whether the first container identifier belongs to the container identifier set to determine whether the container rebuild request indicates to rebuild the limited authorized container; if yes, the first container corresponding to the first container identifier is rebuilt through the interface plug-in according to the container rebuild request to obtain a first rebuilding result; if not, the container rebuild request is intercepted through the interface plug-in. The method stores the container identifier set in the interface plug-in of the container runtime on the edge device to indicate the limited authorized container to be rebuilt on the edge device, receives the container rebuild request issued by the central management system through the interface plug-in, and when it is judged that the first container identifier carried by the container rebuild request belongs to the container identifier set indicating the limited authorized container to be rebuilt on the edge device, the container rebuild request is released and the container rebuild operation is performed; when it is judged that the first container identifier carried by the container rebuild request does not belong to the container identifier set indicating the limited authorized container to be rebuilt on the edge device, the container rebuild request is intercepted and the container rebuild operation is reduced, which can avoid the unintended, large-scale container rebuild operation on the edge device caused by some unintended user operation and autonomous decision of the native component, thereby improving the service quality of the edge device. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0022] Figure 1 A system schematic diagram of a container processing method based on edge cloud provided by an embodiment of the present application;
[0023] Figure 2 A flowchart of a container processing method based on edge cloud provided by an embodiment of the present application;
[0024] Figure 3 A system framework diagram of a container processing method based on edge cloud provided by an embodiment of the present application;
[0025] Figure 4 A system framework diagram of another container processing method based on edge cloud provided by an embodiment of the present application;
[0026] Figure 5An interaction flowchart of a container processing method based on an edge cloud provided in an embodiment of the present application is provided.
[0027] Figure 6 A structure diagram of a container processing device based on an edge cloud provided in an embodiment of the present application is provided.
[0028] Figure 7 A structure diagram of a server provided in an embodiment of the present application is provided.
[0029] Figure 8 A structure diagram of a terminal provided in an embodiment of the present application is provided. DETAILED DESCRIPTION
[0030] The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0031] The edge cloud mainly carries video cloud, content distribution network services, such as live broadcast, on-demand, static, download, etc., and the service quality of the edge device is particularly important. In the edge cloud scenario, considering that the communication link between the edge device and the central control system of the cloud is not stable enough, large-scale container reconstruction operations are prone to occur. A lightweight agent can be deployed on the edge device to communicate with the central control system and cache the central data of the central control system. When the communication link between the edge device and the central control system is abnormal, the lightweight agent temporarily replaces the central control system to enable the container on the edge device to run normally, so as to maintain the service quality of the edge device. However, through research, it is found that there are still some unexpected user operations and autonomous decisions of the native component, which cause the container on the edge device to be unexpectedly and massively reconstructed, thereby reducing the service quality of the edge device.
[0032] The embodiments of the present application provide a container processing method based on an edge cloud. The method stores a container identifier set in an interface plug-in when a container on an edge device runs, indicates the limited authorized reconstruction of the container on the edge device, receives a container reconstruction request issued by a central control system through the interface plug-in, releases the container reconstruction request and performs a container reconstruction operation when it is judged that a first container identifier carried in the container reconstruction request belongs to the container identifier set indicating the limited authorized reconstruction of the container on the edge device, and intercepts the container reconstruction request and reduces the container reconstruction operation when it is judged that the first container identifier carried in the container reconstruction request does not belong to the container identifier set not indicating the limited authorized reconstruction of the container on the edge device. In this way, the unexpected and massive container reconstruction operation on the edge device caused by some unexpected user operations and autonomous decisions of the native component can be avoided, so as to improve the service quality of the edge device.
[0033] Next, the system architecture of the container processing method based on the edge cloud will be introduced. Referring to Figure 1 , Figure 1A system schematic diagram of a container processing method based on an edge cloud is provided for an embodiment of the present application. The system comprises a central management system 101 and an edge device 102, and the edge device 102 is configured to execute the container processing method based on the edge cloud.
[0034] The edge device 102 receives a container reconstruction request sent by the central management system 101 through an interface plug-in of a container runtime; the container reconstruction request carries a first container identifier.
[0035] As an example, the container runtime is denoted as runtime containerd, the interface plug-in is denoted as cri-plugin, and the first container identifier is denoted as id-x; then the central management system 101 sends a container reconstruction request carrying id-x to the edge device 102, and the edge device 102 receives the container reconstruction request carrying id-x sent by the central management system 101 through the cri-plugin of the runtime containerd.
[0036] If the first container identifier belongs to a container identifier set, the edge device 102 performs container reconstruction on a container corresponding to the first container identifier according to the container reconstruction request through the interface plug-in, and obtains a first reconstruction result; the container identifier set is used to indicate containers authorized for limited reconstruction on the edge device.
[0037] As an example, on the basis of the above example, the container identifier set is denoted as ids-1; then the cri-plugin on the edge device 102 maintains ids-1 to indicate containers authorized for limited reconstruction on the edge device 102, and based on this, the edge device 102 judges whether id-x belongs to ids-1 through the cri-plugin; if yes, the container reconstruction request indicates reconstruction of a container authorized for limited reconstruction, and the edge device 102 reconstructs the container corresponding to id-x through the cri-plugin according to the container reconstruction request to obtain the first reconstruction result.
[0038] If the first container identifier does not belong to the container identifier set, the edge device 102 intercepts the container reconstruction request through the interface plug-in.
[0039] As an example, on the basis of the above example of judging whether id-x belongs to ids-1, if no, the container reconstruction request indicates reconstruction of a container unauthorized for reconstruction, and the edge device 102 intercepts the container reconstruction request through the cri-plugin.
[0040] That is, the edge cloud-based container processing method provided in the embodiments of the present application stores a container identification set in an interface plug-in of a container runtime on an edge device, indicates a container that is limited to be authorized to be rebuilt on the edge device, receives a container rebuilding request issued by a central management system through the interface plug-in, when it is judged that a first container identification carried in the container rebuilding request belongs to the container identification set indicating the container that is limited to be authorized to be rebuilt on the edge device, releases the container rebuilding request and performs a container rebuilding operation, when it is judged that the first container identification carried in the container rebuilding request does not belong to the container identification set indicating the container that is limited to be authorized to be rebuilt on the edge device, intercepts the container rebuilding request and reduces the container rebuilding operation, which can avoid unintended user operations, unintended and large-scale container rebuilding operations on the edge device caused by autonomous decisions of native components, and thus improve the service quality of the edge device.
[0041] It should be noted that in the embodiments of the present application, the computer device can be a server or a terminal, and the method provided in the embodiments of the present application can be executed by the terminal or the server alone, or by the terminal and the server in cooperation. Figure 1 Similarly, the corresponding embodiments mainly replace the computer device with a terminal or a server. In addition, when the method provided in the embodiments of the present application is executed by the terminal and the server in cooperation, the steps that need to be reflected on the front-end interface can be executed by the terminal, and some steps that need to be calculated in the background and do not need to be reflected on the front-end interface can be executed by the server.
[0042] The terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart voice interaction device, a vehicle-mounted terminal, a smart television, an extended reality device, an aircraft, or the like, but is not limited thereto. The server can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing basic cloud computing services such as cloud service, cloud database, cloud computing, cloud function, cloud storage, network service, cloud communication, middleware service, domain name service, security service, content distribution network, and big data and artificial intelligence platform, or the like, but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication, which is not limited in the present application. For example, the terminal and the server can be connected through a network, which can be a wired or wireless network.
[0043] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and network to realize data calculation, storage, processing, and sharing in a wide area network or a local area network.
[0044] Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology and other technologies applied on the basis of cloud computing business model, which can form a resource pool and be used on demand. Cloud computing technology will become an important support. The background service of the technical network system needs a large amount of computing and storage resources, such as video websites, picture websites and more portals. With the high development and application of the Internet industry, every item may have its own identification mark in the future, and it needs to be transmitted to the background system for logical processing. Different levels of data will be processed separately, and various industry data will need strong system support, which can only be realized through cloud computing.
[0045] In addition, the embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, assisted driving, autonomous driving, digital people, virtual people, virtual reality, augmented reality, mixed reality, audio and video, etc.
[0046] Next, the container processing method based on edge cloud provided by the embodiments of the present application will be described in detail with the computer device executing the method provided by the embodiments of the present application as an example and in combination with the drawings. Referring to Figure 2 , Figure 2 The flowchart of the container processing method based on edge cloud provided by the embodiments of the present application, the method comprises:
[0047] S201: receiving a container reconstruction request sent by a central management system through an interface plug-in of a container runtime; the container reconstruction request carries a first container identifier.
[0048] In the embodiments of the present application, the central management system can control the edge device to delete a container group, change the container group and change part of the containers in the container group, that is, the central management system can control the edge device to reconstruct the container. In specific implementation, when the central management system sends a container reconstruction request carrying a first container identifier to the edge device, the edge device receives the container reconstruction request carrying the first container identifier sent by the central management system through the interface plug-in of the container runtime.
[0049] Among them, the central management system is used to be responsible for the management, scheduling and operation and maintenance of the container cluster on the edge device; the edge device refers to the device deployed at the network edge far away from the central management system or the cloud environment; the container runtime is used to be responsible for the life cycle management of the container on the edge device, including the start, stop and restart of the container; the interface plug-in of the container runtime refers to the component used to realize the communication between the proxy component kubelet on the edge device and the container runtime runtime containerd; the container reconstruction request refers to the request for controlling the edge device to reconstruct the container, that is, the request for controlling the edge device to delete the container or the request for controlling the edge device to change the container; the first container identifier refers to the identifier corresponding to the container to be reconstructed.
[0050] The S201 receives a container reconstruction request carrying a first container identifier sent by the center management system through the interface plug-in of the container runtime on the edge device, can obtain unexpected user operations, unexpected container reconstruction requests generated by autonomous decision of the native component, and provides a basis for subsequent avoidance of unexpected and large-scale container reconstruction operations on the edge device; and the first container identifier provides a basis for subsequent judgment of whether the container reconstruction request represents a container for limited authorized reconstruction.
[0051] As an example of S201, the center management system sends a container reconstruction request carrying a first container identifier id-x to the edge device, and the edge device receives the container reconstruction request carrying id-x sent by the center management system through the interface plug-in cri-plugin of the container runtime runtime containerd.
[0052] S202: If the first container identifier belongs to a container identifier set, perform container reconstruction on the container corresponding to the first container identifier according to the container reconstruction request through the interface plug-in, and obtain a first reconstruction result; the container identifier set is used to indicate the container for limited authorized reconstruction on the edge device.
[0053] In the related art, a lightweight agent is deployed on the edge device to communicate with the center management system and cache the center data of the center management system. When the communication link between the edge device and the center management system is abnormal, the lightweight agent temporarily replaces the center management system to make the container on the edge device run normally, so as to maintain the service quality of the edge device. However, through research, it is found that there are still some unexpected user operations and autonomous decisions of the native component, which cause the container on the edge device to be unexpectedly and massively reconstructed, and reduce the service quality of the edge device.
[0054] Therefore, in the embodiments of the present application, in order to solve the above problems, considering the container on the edge device performing small-scale reconstruction of limited authorized reconstruction, intercepting the container of large-scale reconstruction of unauthorized reconstruction, some unintended user operations, and large-scale container reconstruction operations on the edge device caused by autonomous decision of the native component can be avoided, so as to improve the service quality of the edge device. Based on this, the center control system needs to issue a container identifier set to the edge device to indicate the limited authorized reconstruction container on the edge device, and maintain the container identifier set in the interface plug-in of the container runtime on the edge device; after the edge device receives the container reconstruction request carrying the first container identifier sent by the center control system through the interface plug-in of the container runtime in S201, it is judged through the interface plug-in whether the first container identifier belongs to the container identifier set, whether the container reconstruction request represents the reconstruction of the limited authorized reconstruction container can be judged, if yes, that is, the first container identifier belongs to the container identifier set, indicating that the container reconstruction request is used to reconstruct the limited authorized reconstruction container, and if no, that is, the first container identifier does not belong to the container identifier set, indicating that the container reconstruction request is an unintended container reconstruction request generated by unintended user operation or autonomous decision of the native component, then the container corresponding to the first container identifier is reconstructed through the interface plug-in according to the container reconstruction request to obtain the first reconstruction result.
[0055] Wherein, the container identifier set refers to the set formed by the identifiers of the limited authorized reconstruction containers on the edge device; when the container reconstruction request is a request for controlling the edge device to delete the container, the container reconstruction is container deletion, and the first reconstruction result is the result of the edge device deleting the container corresponding to the first container identifier; when the container reconstruction request is a request for controlling the edge device to change the container, the container reconstruction is container change, and the first reconstruction result is the result of the edge device changing the container corresponding to the first container identifier.
[0056] When the first container identifier carried by the container reconstruction request belongs to the container identifier set indicating the limited authorized reconstruction container on the edge device through the interface plug-in in S202, the container reconstruction request is released and the container reconstruction operation is performed, indicating that the limited authorized reconstruction container on the edge device is allowed to be reconstructed in a small scale, so as to guarantee the service quality of the edge device.
[0057] As an example of S202, on the basis of the example of S201 above, the interface plug-in cri-plugin on the edge device maintains a container identifier set ids-1 to indicate the limited authorized reconstruction container on the edge device; the edge device judges whether the first container identifier id-x belongs to ids-1 through cri-plugin, if id-x belongs to ids-1, the edge device reconstructs the container corresponding to id-x according to the container reconstruction request through cri-plugin to obtain the first reconstruction result. This way indicates that the limited authorized reconstruction container corresponding to ids-1 on the edge device is allowed to be reconstructed in a small scale, so as to guarantee the service quality of the edge device.
[0058] S203: If the first container identifier does not belong to the container identifier set, intercept the container reconstruction request through the interface plug-in.
[0059] In the embodiment of the application, after the edge device executes S201 and the interface plug-in of the container runtime receives the container reconstruction request carrying the first container identifier sent by the central management system, the interface plug-in is used to determine whether the first container identifier belongs to the container identifier set, so as to determine whether the container reconstruction request represents the reconstruction of the container with limited authorization; if not, that is, the first container identifier does not belong to the container identifier set, it indicates that the container reconstruction request is used to reconstruct the container without authorization, which is an unexpected container reconstruction request generated by an unexpected user operation or autonomous decision of a native component, and the container reconstruction request is intercepted through the interface plug-in.
[0060] When the S203 determines that the first container identifier carried in the container reconstruction request does not belong to the container identifier set, which does not indicate the container with limited authorization on the edge device, the container reconstruction request is intercepted, and the container reconstruction operation is reduced, which can avoid the unexpected and large-scale container reconstruction operation on the edge device caused by some unexpected user operations or autonomous decisions of native components, so as to improve the service quality of the edge device.
[0061] As an example of S203, based on the example of S202 above, if id-x does not belong to ids-1, the edge device intercepts the container reconstruction request through the interface plug-in cri-plugin.
[0062] It can be seen from the above technical solution that the interface plug-in of the container runtime on the edge device maintains a container identifier set to indicate the containers authorized for limited reconstruction on the edge device. Based on this, when the central management system sends a container reconstruction request carrying a first container identifier to the edge device, the edge device first receives the container reconstruction request carrying the first container identifier sent by the central management system through the interface plug-in. Then, it is judged whether the first container identifier belongs to the container identifier set to determine whether the container reconstruction request indicates the reconstruction of the containers authorized for limited reconstruction. If yes, the first container identifier corresponding container is reconstructed through the interface plug-in according to the container reconstruction request to obtain a first reconstruction result. If no, the container reconstruction request is intercepted through the interface plug-in. This method stores the container identifier set in the interface plug-in of the container runtime on the edge device to indicate the containers authorized for limited reconstruction on the edge device. The container reconstruction request issued by the central management system is received through the interface plug-in. When it is judged that the first container identifier carried by the container reconstruction request belongs to the container identifier set indicating the containers authorized for limited reconstruction on the edge device, the container reconstruction request is released and the container reconstruction operation is performed. When it is judged that the first container identifier carried by the container reconstruction request does not belong to the container identifier set indicating the containers authorized for limited reconstruction on the edge device, the container reconstruction request is intercepted and the container reconstruction operation is reduced. This can avoid the unintended, large-scale container reconstruction operation on the edge device caused by some unintended user operations and autonomous decisions of the native components, thereby improving the service quality of the edge device.
[0063] In the embodiments of the present application, it is considered that the interface plug-in of the container runtime is used to realize the communication between the proxy component kubelet on the edge device and the container runtime, and the container runtime is used to be responsible for the life cycle management of the containers on the edge device, including the start, stop, restart, etc. of the containers. Therefore, when S202 is specifically implemented, if the first container identifier belongs to the container identifier set, the interface plug-in communicates the container reconstruction request to the container runtime, so that the container reconstruction is truly realized by the container runtime. Specifically, the container reconstruction request is released to the container runtime through the interface plug-in, so that the first container identifier corresponding container is reconstructed according to the container reconstruction request through the container runtime to obtain a first reconstruction result. Based on this, the present application provides a possible implementation manner, and S202 includes the following S202a-S202b (not shown in the figure).
[0064] S202a: releasing the container reconstruction request to the container runtime through the interface plug-in.
[0065] S202b: performing container reconstruction on the first container identifier corresponding container according to the container reconstruction request through the container runtime to obtain a first reconstruction result.
[0066] As an example of S202a-S202b, on the basis of the example of S202 described above, the edge device sends a container reconstruction request to the container runtime runtime containerd through the interface plug-in cri-plugin, and the runtime containerd reconstructs the container corresponding to the first container identifier id-x according to the container reconstruction request to obtain a first reconstruction result.
[0067] In the embodiments of the present application, considering that one or more containers can be encapsulated into a container group, the small-scale reconstruction of the limited authorized container actually refers to: deleting the limited authorized container group, changing the limited authorized container group, and changing the limited authorized container in the container group; therefore, the identifier corresponding to the limited authorized container on the edge device, that is, the container identifier set, can include the limited authorized container group identifier of the container group granularity, or the limited authorized container group identifier of the container group granularity, or the limited authorized container identifier of the container granularity, and the combination of any two or three. Based on this, the present application provides a possible implementation manner, and the container identifier set includes one or more of the limited authorized container group identifier, the limited authorized container group identifier, and the limited authorized container identifier on the edge device.
[0068] As an example, the container identifier set ids-1 includes one or more of the limited authorized container group identifier pod id, the limited authorized pod id, and the limited authorized container identifier container id on the edge device.
[0069] Further, in the embodiments of the present application, further considering avoiding the container identification set indicating the limited authorized reconstruction containers on the edge device being always reconstructed, some unintended user operations, native component autonomous decision leading to unintended and large-scale container reconstruction operations on the edge device can be further avoided; therefore, the central management system can configure a first recycling time for the target container identification in the container identification set, generate a first recycling request for the target container identification in the container identification set when the use time of the target container identification in the container identification set is the first recycling time, so as to control the edge device to mark the target container identification in the container identification set for recycling; that is, the central management system sends the first recycling request for the target container identification in the container identification set to the edge device, the edge device receives the first recycling request for the target container identification in the container identification set through the interface plug-in, marks the target container identification in the container identification set for recycling, and obtains the recycled target container identification. On this basis, when the edge device judges that the first container identification is the recycled target container identification through the interface plug-in, it indicates that the container reconstruction request is used to reconstruct the recycled authorized reconstruction container, and it is also an unintended container reconstruction request generated by unintended user operation or native component autonomous decision, and then the container reconstruction request is intercepted through the interface plug-in. Based on this, the present application provides a possible implementation manner, and the method further includes the following S1-S2 (not shown in the figure).
[0070] S1: If the first recycling request for the target container identification in the container identification set sent by the central management system is received, marking the target container identification in the container identification set for recycling according to the first recycling request, and obtaining the recycled target container identification; the first recycling request is generated by the central management system when the use time of the target container identification in the container identification set is the first recycling time.
[0071] S2: If the first container identification is the recycled target container identification, the container reconstruction request is intercepted through the interface plug-in.
[0072] Among them, the target container identification in the container identification set can be any one of the container identification in the container identification set, and the use time of the target container identification in the container identification set refers to the existence time of the target container identification in the container identification set maintained by the interface plug-in on the edge device; the first recycling time refers to the upper limit time of container authorized reconstruction set according to actual container reconstruction demand.
[0073] As an example of S1-S2, on the basis of the above examples of S201-S203, the central management system configures the first recovery time as T1 for the target container identifier id-z in the container identifier set ids-1, judges that the use time of id-z in ids-1 is T1, generates the first recovery request for id-z in ids-1, and sends the first recovery request for id-z in ids-1 to the edge device; the edge device receives the first recovery request for id-z in ids-1 through the interface plug-in cri-plugin, recovers and marks id-z in ids-1, and obtains the recovered and marked id-z. When the edge device judges that the first container identifier id-x is the recovered and marked id-z through the cri-plugin, the edge device intercepts the container reconstruction request through the cri-plugin.
[0074] In summary, referring to Figure 3 , Figure 3 A system framework diagram of a container processing method based on an edge cloud is provided for the embodiments of the present application; the system framework includes an application programming interface server apiserver in a central management system, and a proxy component kubelet, an interface plug-in cri-plugin, a container runtime runtime containerd, a container adapter containerd-shim, and a container group pod on an edge device.
[0075] The central management system sends a container identifier set ids-1 to the edge device through the apiserver, and the edge device receives and maintains ids-1 sent by the central management system through the cri-plugin, wherein ids-1 indicates a limited authorized container for reconstruction on the edge device.
[0076] The central management system sends a container reconstruction request carrying the first container identifier id-x to the edge device, the edge device receives the container reconstruction request carrying id-x sent by the central management system through kubelet, thereby receiving the container reconstruction request carrying id-x sent by the central management system through cri-plugin; the edge device judges whether the first container identifier id-x belongs to ids-1 through cri-plugin, if id-x belongs to ids-1, the edge device releases the container reconstruction request to the container runtime runtime containerd through cri-plugin, and reconstructs the container corresponding to the first container identifier id-x through runtime containerd according to the container reconstruction request to obtain the first reconstruction result, that is, reconstructs the container corresponding to container id-x in the container group pod through runtime containerd to obtain the first reconstruction result through containerd-shim; if id-x does not belong to ids-1, the edge device intercepts the container reconstruction request through the interface plug-in cri-plugin.
[0077] In addition, in the embodiments of the present application, further considering the process termination signals between some unexpected processes on the edge device, which leads to the unexpected large-scale reconstruction of containers on the edge device, reducing the service quality of the edge device; in order to solve this problem, considering that the source process terminates the target process on the edge device with limited authorization to reconstruct the containers with limited authorization in a small scale, and intercepting the source process that terminates the target process without authorization to intercept the large-scale reconstruction of the containers without authorization, some unexpected process termination signals between processes can be further avoided to cause unexpected and large-scale container reconstruction operations on the edge device, thereby further improving the service quality of the edge device.
[0078] Based on this, the center control system needs to issue an inter-process identifier set to the edge device to indicate the source process with limited authorization to terminate the destination process and the container with limited authorization to be reconstructed, and maintain the inter-process identifier set on the edge device. The edge device obtains a process termination signal between the first process and the second process carrying an inter-process container identifier, judges whether the inter-process container identifier belongs to the inter-process identifier set and whether the inter-process container identifier includes the second container identifier, and can judge whether the process termination signal indicates that the source process with limited authorization terminates the destination process to reconstruct the container with limited authorization to be reconstructed; if yes, that is, the process termination signal belongs to the inter-process identifier set and the inter-process container identifier includes the second container identifier, it indicates that the process termination signal is used to reconstruct the container with limited authorization to be reconstructed, and is not an unexpected process termination signal between processes, and then the container corresponding to the second container identifier is reconstructed according to the process termination signal to obtain a second reconstruction result; if not, that is, the process termination signal does not belong to the inter-process identifier set, it indicates that the process termination signal is an unexpected process termination signal between processes, and then the process termination signal is intercepted. Therefore, the present application provides a possible implementation manner, and the method further includes the following S3-S5 (not shown in the figure).
[0079] S3: Obtain a process termination signal between the first process and the second process; the process termination signal carries an inter-process container identifier.
[0080] S4: If the inter-process container identifier belongs to the inter-process identifier set and the inter-process container identifier includes the second container identifier, perform container reconstruction on the container corresponding to the second container identifier according to the process termination signal to obtain a second reconstruction result; the inter-process identifier set is used to indicate the source process with limited authorization to terminate the destination process and the container with limited authorization to be reconstructed on the edge device.
[0081] S5: If the inter-process container identifier does not belong to the inter-process identifier set, intercept the process termination signal.
[0082] Wherein, the first process and the second process are different processes of the edge device; the process termination signal is a signal sent by the first process to the second process to terminate the second process; the inter-process container identifier at least includes the process identifier of the first process and the process identifier of the second process; the second container identifier is an identifier corresponding to a container to be reconstructed; the inter-process identifier set is a set formed by the source process identifier and the destination process identifier corresponding to the source process with limited authorization to terminate the destination process, and the identifier corresponding to the container with limited authorization to be reconstructed on the edge device; when the process termination signal is used to terminate the second process and delete the container, the container reconstruction is container deletion, and the second reconstruction result is the result of deleting the container corresponding to the second container identifier by the edge device; when the process termination signal is used to terminate the second process and change the container, the container reconstruction is container change, and the second reconstruction result is the result of changing the container corresponding to the second container identifier by the edge device.
[0083] The S3-S5 stores an inter-process identification set on the edge device, indicates a limited authorized source process terminating a destination process and a limited authorized container to be rebuilt on the edge device, when an inter-process container identification carried by a process termination signal between a first process and a second process is obtained, it is judged that the inter-process container identification carried by the process termination signal belongs to the inter-process identification set, indicates the limited authorized source process terminating the destination process and the limited authorized container to be rebuilt on the edge device, the process termination signal is released and the container rebuilding operation is performed, when it is judged that the inter-process container identification carried by the process termination signal does not belong to the inter-process identification set, does not indicate the limited authorized source process terminating the destination process and the limited authorized container to be rebuilt on the edge device, the process termination signal is intercepted and the container rebuilding operation is reduced, which can further avoid some unexpected process termination signals between processes on the edge device, resulting in unexpected and large-scale container rebuilding operations on the edge device, thereby further improving the service quality of the edge device.
[0084] As an example of S3-S5, the central control system needs to send an inter-process identification set ids-2 to the edge device to indicate a limited authorized source process terminating a destination process and a limited authorized container to be rebuilt on the edge device; the edge device receives ids-2 sent by the central control system and maintains ids-2. The edge device obtains a process termination signal carrying an inter-process container identification between a first process and a second process, judges whether the inter-process container identification belongs to ids-2 and whether the inter-process container identification includes a second container identification id-y, if yes, the container corresponding to id-y is rebuilt according to the process termination signal to obtain a second reconstruction result; if not, the process termination signal is intercepted.
[0085] In the embodiment of the application, when the first process and the second process are both device processes, the process termination signal between the first process and the second process is used for the first process to terminate the second process without rebuilding the container; and the inter-process container identification carried by the process termination signal includes the process identification of the first process and the process identification of the second process.
[0086] When the first process is a device process and the second process is a container process, the process termination signal between the first process and the second process is used for the first process to terminate the second process and rebuild the container; and the inter-process container identification carried by the process termination signal includes the process identification of the first process, the process identification of the second process and the second container identification.
[0087] When the first process is a different process in the same namespace in the container, the process termination signal between the first process and the second process is used for the first process to terminate the second process and rebuild the container; and the inter-process container identification carried by the process termination signal includes the process identification of the first process, the process identification of the second process and the second container identification.
[0088] Based on this, the application provides a possible implementation manner. If the first process and the second process are different device processes in the same device, the inter-process container identifier includes the process identifier of the first process and the process identifier of the second process. If the first process is a device process and the second process is a container process, the inter-process container identifier includes the process identifier of the first process, the process identifier of the second process, and the second container identifier. If the first process and the second process are different processes in the same namespace in a container, the inter-process container identifier includes the process identifier of the first process, the process identifier of the second process, and the second container identifier.
[0089] In the embodiment of the application, considering that one or more containers can be encapsulated into a container group, the limited authorization reconstruction of the small-scale container actually refers to: deleting the limited authorization container group, changing the limited authorization container group, and changing the limited authorization container in the container group. Therefore, the identifier corresponding to the limited authorization reconstructed container on the edge device in the inter-process identifier set can include the container group granularity limited authorization deleted container group identifier, or the container group granularity limited authorization changed container group identifier, or the container granularity limited authorization changed container identifier, and the combination of any two or three. Based on this, the application provides a possible implementation manner. The inter-process identifier set includes one or more of the limited authorization deleted container group identifier, the limited authorization changed container group identifier, and the limited authorization changed container identifier on the edge device.
[0090] As an example, the inter-process identifier set ids-2 includes one or more of the limited authorization deleted container group identifier pod id, the limited authorization changed pod id, and the limited authorization changed container identifier container id on the edge device.
[0091] In the embodiment of the application, in order to avoid the central control system from continuously issuing the inter-process identifier set to the edge device, to avoid the release of a large number of process termination signals between processes, and to further avoid some unexpected process termination signals between processes from causing unexpected and large-scale container reconstruction operations on the edge device, the edge device needs to obtain the release index of the process termination signal and report the release index to the central control system, so that the central control system judges whether the release index is less than or equal to the index threshold, and issues the inter-process identifier set to the edge device. Based on this, the application provides a possible implementation manner. The obtaining step of the inter-process identifier set includes the following S6-S8 (not shown in the figure):
[0092] S6: Obtain the release index of the process termination signal on the edge device.
[0093] S7: Send the release index to the central control system.
[0094] S8: If the release index of the process termination signal is less than or equal to the index threshold value, the receiving center control system sends an inter-process identifier set.
[0095] In the embodiment, the release index of the process termination signal on the edge device includes the release number of the process termination signal on the edge device, and the index threshold value is a number threshold value. The release index of the process termination signal on the edge device includes the release proportion of the process termination signal on the edge device, and the index threshold value is a proportion threshold value.
[0096] The S6-S8 edge device reports the release index of the process termination signal to the center control system. When the center control system determines that the release index is less than or equal to the index threshold value, the center control system issues an inter-process identifier set to the edge device, which can control the release of the process termination signal on the edge device and avoid the release of a large number of process termination signals between processes. In this way, the edge device can further avoid the non-expected large-scale container reconstruction operation caused by the process termination signal between processes, thereby further improving the service quality of the edge device.
[0097] In addition, in the embodiment, when it is determined that the first process and the second process are different processes in the same container under the same control group, the process termination signal between the different processes in the same container under the same control group is not a process termination signal between non-expected processes, and the process termination signal between the different processes in the same container under the same control group is released to implement container reconstruction. The process inter-container identifier carried by the process termination signal between the first process and the second process includes a second container identifier, and the container corresponding to the second container identifier is reconstructed according to the process termination signal to obtain a second reconstruction result. Based on this, the present application provides a possible implementation manner. The method further includes S9 (not shown in the figure): if the first process and the second process are different processes in the same container under the same control group, the container corresponding to the second container identifier in the process inter-container identifier is reconstructed according to the process termination signal to obtain a second reconstruction result.
[0098] S9 releases the process termination signal between the first process and the second process and performs a container reconstruction operation when it is determined that the first process and the second process are different processes in the same container under the same control group, which means that the source process termination destination process in the same container under the same control group on the edge device is allowed to implement a small-scale reconstruction container, thereby further improving the service quality of the edge device.
[0099] As an example of S9, based on the example of S3-S5, when it is determined that the first process and the second process are different processes in the same container under the same control group cgroup, the container corresponding to the second container identifier id-y is reconstructed according to the process termination signal to obtain a second reconstruction result.
[0100] In the embodiments of the present application, further considering avoiding the continuous growth of inter-process identifiers in the inter-process identifier set, the service performance of the edge device can be improved; therefore, the central management system can configure a second recycling time for the target inter-process identifier in the inter-process identifier set, generate a second recycling request for the target inter-process identifier in the inter-process identifier set when the use time of the target inter-process identifier in the inter-process identifier set is the second recycling time, so as to control the edge device to recycle the target inter-process identifier from the inter-process identifier set. That is, the central management system sends a second recycling request for the target inter-process identifier in the inter-process identifier set to the edge device, and the edge device receives the second recycling request for the target inter-process identifier in the inter-process identifier set and recycles the target inter-process identifier from the inter-process identifier set. Based on this, the present application provides a possible implementation manner, and the method further includes S10 (not shown in the figure): if the second recycling request for the target inter-process identifier in the inter-process identifier set sent by the central management system is received, recycling the target inter-process identifier from the inter-process identifier set according to the second recycling request; the second recycling request is generated by the central management system when the use time of the target inter-process identifier is the second recycling time.
[0101] In the embodiments of the present application, further considering avoiding the continuous growth of inter-process identifiers in the inter-process identifier set, the service performance of the edge device can be improved; therefore, the central management system can configure a second recycling time for the target inter-process identifier in the inter-process identifier set, generate a second recycling request for the target inter-process identifier in the inter-process identifier set when the use time of the target inter-process identifier in the inter-process identifier set is the second recycling time, so as to control the edge device to recycle the target inter-process identifier from the inter-process identifier set. That is, the central management system sends a second recycling request for the target inter-process identifier in the inter-process identifier set to the edge device, and the edge device receives the second recycling request for the target inter-process identifier in the inter-process identifier set and recycles the target inter-process identifier from the inter-process identifier set. Based on this, the present application provides a possible implementation manner, and the method further includes S10 (not shown in the figure): if the second recycling request for the target inter-process identifier in the inter-process identifier set sent by the central management system is received, recycling the target inter-process identifier from the inter-process identifier set according to the second recycling request; the second recycling request is generated by the central management system when the use time of the target inter-process identifier is the second recycling time.
[0102] As an example of S10, on the basis of the examples of S3-S5 described above, the central management system configures a second recycling time T2 for the target inter-process identifier in the inter-process identifier set ids-2, generates a second recycling request for the target inter-process identifier in ids-2 when the use time of the target inter-process identifier in ids-2 is T2, and sends the second recycling request for the target inter-process identifier in ids-2 to the edge device; the edge device receives the second recycling request for the target inter-process identifier in ids-2 and recycles the target inter-process identifier from ids-2.
[0103] Further, in the embodiments of the present application, considering that the edge device executes the source process of limited authorization to terminate the non-reconstruction container of the destination process, the service quality and service performance of the edge device can be further improved; after the edge device obtains the process termination signal carrying the inter-process container identifier between the first process and the second process, it is further needed to judge whether the inter-process container identifier belongs to the inter-process identifier set and whether the container identifier in the inter-process container identifier is empty, so as to judge whether the process termination signal represents the source process of limited authorization to terminate the non-reconstruction container of the destination process; if yes, that is, the inter-process container identifier belongs to the inter-process identifier set and the container identifier in the inter-process container identifier is empty, it represents that the process termination signal is used for the first process to terminate the second process non-reconstruction container, which is not the process termination signal between the non-expected processes, and then the process termination signal is released to implement the first process to terminate the second process. Based on this, the present application provides a possible implementation manner, and the method further includes S11 (not shown in the figure): if the inter-process container identifier belongs to the inter-process identifier set and the container identifier in the inter-process container identifier is empty, the process termination signal is released.
[0104] The S11 determines that the first process and the second process are both device processes when the inter-process container identifier belongs to the inter-process identifier set and the container identifier in the inter-process container identifier is empty, the process termination signal between the first process and the second process is used for the first process to terminate the second process non-reconstruction container, the process termination signal between the first process and the second process is released, which represents that the edge device is allowed to execute the source process of limited authorization to terminate the non-reconstruction container of the destination process, so as to further guarantee the service quality and service performance of the edge device.
[0105] On the basis of the above description, referring to Figure 4 , Figure 4 Another system framework diagram of the container processing method based on the edge cloud provided by the embodiments of the present application is provided; the system framework includes a central control system and an edge device. The edge device reports the release index of the process termination signal to the central control system, the central control system judges that the release index is less than or equal to the index threshold value, and then issues the inter-process identifier set ids-2 to the edge device, and the edge device receives the ids-2 sent by the central control system and maintains the ids-2, wherein the ids-2 indicates the source process of limited authorization and the reconstruction container of limited authorization of the destination process on the edge device.
[0106] The edge device obtains the process termination signal carrying the inter-process container identifier between the first process and the second process, judges whether the inter-process container identifier belongs to the ids-2 and whether the inter-process container identifier includes the second container identifier id-y, if yes, obtains the second reconstruction result according to the process termination signal to reconstruct the container corresponding to the id-y; if not, intercepts the process termination signal.
[0107] The ids-2 includes source process identification and destination process identification corresponding to a source process termination destination process of a limited authorized source process on the edge device, and identification corresponding to a limited authorized container.
[0108] In addition, when the edge device judges that the first process and the second process are different processes in a container under the same control group cgroup, the edge device obtains a second reconstruction result according to a container corresponding to the second container identification id-y being reconstructed according to the process termination signal. When the edge device judges that the inter-process container identification belongs to the inter-process identification set and the container identification in the inter-process container identification is empty, the edge device releases the process termination signal.
[0109] In summary, refer to Figure 5 , Figure 5 An interaction flowchart of a container processing method based on an edge cloud is provided for an embodiment of the application. The interaction flowchart includes: a still-standing double-channel release controller requesting an inter-process identification set to be issued by a center control system, the center control system issuing the inter-process identification set to an edge device, the still-standing requesting a container identification set to be issued by the center control system, the center control system issuing the container identification set to the edge device, the edge device performing cloud-native link release and interception, and the edge device performing kernel signal release and interception.
[0110] The still-standing requesting the inter-process identification set to be issued by the center control system refers to: after the still-standing receives a container reconstruction request carrying a first container identification id-x, the still-standing first requests the center control system to issue the inter-process identification set ids-2.
[0111] The center control system issuing the inter-process identification set to the edge device refers to: when the center control system judges that a release index of a process termination signal sent by the edge device is less than or equal to an index threshold, the center control system sends the ids-2 to the edge device through an application programming interface server apiserver. The edge device receives the ids-2 sent by the center control system and maintains the ids-2, where the ids-2 indicates a limited authorized source process termination destination process on the edge device and a limited authorized container.
[0112] The still-standing requesting the container identification set to be issued by the center control system refers to: after the center control system issues the inter-process identification set to the edge device, the still-standing further requests the center control system to issue the container identification set ids-1.
[0113] The center management system issuing a container identifier set to the edge device refers to the center management system sending the container identifier set ids-1 to the edge device through the apiserver, and the edge device receiving and maintaining ids-1 sent by the center management system through the interface plug-in cri-plugin, wherein ids-1 indicates a container authorized for limited reconstruction on the edge device.
[0114] The edge device performing cloud native link release and interception refers to the center management system also sending a container reconstruction request carrying id-x to the edge device through the apiserver, the edge device receiving the container reconstruction request carrying id-x sent by the center management system through the cri-plugin, judging whether id-x belongs to ids-1 through the cri-plugin, if id-x belongs to ids-1, reconstructing the container corresponding to the first container identifier id-x according to the container reconstruction request through the cri-plugin to obtain a first reconstruction result, and if id-x does not belong to ids-1, intercepting the container reconstruction request through the cri-plugin.
[0115] The edge device performing kernel signal release and interception refers to the edge device obtaining a process termination signal carrying an inter-process container identifier between the first process and the second process, judging whether the inter-process container identifier belongs to ids-2 and whether the inter-process container identifier includes the second container identifier id-y, if yes, reconstructing the container corresponding to id-y according to the process termination signal to obtain a second reconstruction result, and if no, intercepting the process termination signal.
[0116] In addition, the interaction process further includes the center management system issuing a container identifier set recovery strategy to the edge device and the center management system issuing an inter-process identifier set recovery strategy to the edge device.
[0117] The center management system issuing a container identifier set recovery strategy to the edge device refers to the center management system configuring a first recovery time T1 for a target container identifier id-z in ids-1, generating a first recovery request for id-z in ids-1 when the use time of id-z in ids-1 is T1, and sending the first recovery request for id-z in ids-1 to the edge device; the edge device receiving the first recovery request for id-z in ids-1 through the cri-plugin, marking id-z in ids-1 for recovery to obtain a recovery marked id-z; and the edge device judging id-x as the recovery marked id-z through the cri-plugin, and intercepting the container reconstruction request through the cri-plugin.
[0118] The recovery strategy of the center management system to the edge device for the inter-process identification set is that the center management system configures a second recovery time as T2 for the target inter-process identification in the ids-2, judges that the use time of the target inter-process identification in the ids-2 is T2, generates a second recovery request for the target inter-process identification in the ids-2, and sends the second recovery request for the target inter-process identification in the ids-2 to the edge device; and the edge device receives the second recovery request for the target inter-process identification in the ids-2, and recovers the target inter-process identification from the ids-2.
[0119] It should be noted that, on the basis of the implementation manners provided in the above aspects, the application can be further combined to provide more implementation manners.
[0120] Based on Figure 2 The container processing method based on the edge cloud provided in the corresponding embodiment, the application embodiment also provides a container processing device based on the edge cloud, see Figure 6 , Figure 6 A structure diagram of the container processing device based on the edge cloud provided by the application embodiment, the container processing device 600 is deployed on the edge device, and includes a receiving unit 601, a reconstruction unit 602 and an interception unit 603.
[0121] The receiving unit 601 is configured to receive a container reconstruction request sent by the center management system through an interface plug-in of a container runtime; the container reconstruction request carries a first container identification;
[0122] The reconstruction unit 602 is configured to, if the first container identification belongs to a container identification set, perform container reconstruction on a container corresponding to the first container identification according to the container reconstruction request through the interface plug-in, and obtain a first reconstruction result; the container identification set is used to indicate a container that is limitedly authorized to be reconstructed on the edge device;
[0123] The interception unit 603 is configured to, if the first container identification does not belong to the container identification set, intercept the container reconstruction request through the interface plug-in.
[0124] In a possible implementation manner, the reconstruction unit 602 is configured to:
[0125] Release the container reconstruction request to the container runtime through the interface plug-in;
[0126] Perform container reconstruction on the container corresponding to the first container identification according to the container reconstruction request through the container runtime, and obtain the first reconstruction result.
[0127] In a possible implementation manner, the container identification set includes one or more of a container group identification that is limitedly authorized to be deleted on the edge device, a container group identification that is limitedly authorized to be changed, and a container identification that is limitedly authorized to be changed.
[0128] In a possible implementation, the apparatus further includes a marking unit.
[0129] The marking unit is configured to, if a first recovery request for a target container identifier in the container identifier set is received from the central management system, mark the target container identifier in the container identifier set according to the first recovery request, and obtain the target container identifier after the marking.
[0130] The intercepting unit 603 is further configured to, if the first container identifier is the target container identifier after the marking, intercept the container reconstruction request through the interface plug-in.
[0131] In a possible implementation, the apparatus further includes an obtaining unit.
[0132] The obtaining unit is configured to obtain a process termination signal between the first process and the second process, and the process termination signal carries an inter-process container identifier.
[0133] The reconstruction unit 602 is further configured to, if the inter-process container identifier belongs to an inter-process identifier set and the inter-process container identifier includes the second container identifier, perform container reconstruction on a container corresponding to the second container identifier according to the process termination signal, and obtain a second reconstruction result.
[0134] The intercepting unit 603 is configured to, if the inter-process container identifier does not belong to the inter-process identifier set, intercept the process termination signal.
[0135] In a possible implementation, if the first process and the second process are different device processes in the same device, the inter-process container identifier includes a process identifier of the first process and a process identifier of the second process.
[0136] If the first process is a device process and the second process is a container process, the inter-process container identifier includes a process identifier of the first process, a process identifier of the second process, and the second container identifier.
[0137] If the first process and the second process are different processes in the same namespace in a container, the inter-process container identifier includes a process identifier of the first process, a process identifier of the second process, and the second container identifier.
[0138] In a possible implementation, the inter-process identifier set includes one or more of a container group identifier authorized to be deleted on the edge device, a container group identifier authorized to be changed, and a container identifier authorized to be changed.
[0139] In a possible implementation, the apparatus further includes a sending unit.
[0140] The acquisition unit is further configured to acquire a release index of the process termination signal on the edge device.
[0141] The sending unit is configured to send the release index to the central management system.
[0142] The receiving unit 601 is further configured to receive an inter-process identification set sent by the central management system if the release index is less than or equal to the index threshold.
[0143] In a possible implementation, the reconstruction unit 602 is further configured to:
[0144] If the first process and the second process are different processes in a container under the same control group, the container corresponding to the second container identification in the inter-process container identification is reconstructed according to the process termination signal, and a second reconstruction result is obtained.
[0145] In a possible implementation, the apparatus further includes a recycling unit.
[0146] The recycling unit is configured to recycle a target inter-process identification from the inter-process identification set according to a second recycling request sent by the central management system if the second recycling request for the target inter-process identification in the inter-process identification set is received. The second recycling request is generated by the central management system when the use time of the target inter-process identification in the inter-process identification set is a second recycling time.
[0147] In a possible implementation, the apparatus further includes a release unit.
[0148] The release unit is configured to release the process termination signal if the inter-process container identification belongs to the inter-process identification set and the container identification in the inter-process container identification is empty.
[0149] It can be seen from the above technical solution that the interface plug-in during the container runtime on the edge device maintains a container identification set to indicate the container with limited authorization to be rebuilt on the edge device; based on this, when the central control system sends a container reconstruction request carrying a first container identification to the edge device, the edge device first receives the container reconstruction request carrying the first container identification sent by the central control system through the interface plug-in; then, it is determined whether the first container identification belongs to the container identification set to determine whether the container reconstruction request indicates the reconstruction of a container with limited authorization to be rebuilt. If so, the interface plug-in is used to reconstruct the container corresponding to the first container identification according to the container reconstruction request to obtain a first reconstruction result; if not, the container reconstruction request is intercepted by the interface plug-in. It can be seen that the interface plug-in stores the container identification set when the container is running on the edge device, indicating the container with limited authorization to be rebuilt on the edge device, and receives the container reconstruction request issued by the central management and control system through the interface plug-in. When it is judged that the first container identification carried by the container reconstruction request belongs to the container identification set indicating the container with limited authorization to be rebuilt on the edge device, the container reconstruction request is released and the container reconstruction operation is performed. When it is judged that the first container identification carried by the container reconstruction request does not belong to the container identification set and does not indicate the container with limited authorization to be rebuilt on the edge device, the container reconstruction request is intercepted and the container reconstruction operation is reduced. This can avoid unexpected and large-scale container reconstruction operations on edge devices caused by some unexpected user operations and autonomous decisions of native components, thereby improving the service quality of edge devices.
[0150] The present application also provides a computer device, which may be a server. Figure 7 , Figure 7 A structural diagram of a server provided in an embodiment of the present application, wherein the server 700 may have relatively large differences due to different configurations or performances, and may include one or more processors, such as a CPU 722, and a memory 732, one or more storage media 730 (such as one or more massive storage devices) storing application programs 742 or data 744. Among them, the memory 732 and the storage medium 730 may be temporary storage or persistent storage. The program stored in the storage medium 730 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 722 may be configured to communicate with the storage medium 730 to execute a series of instruction operations in the storage medium 730 on the server 700.
[0151] The server 700 may also include one or more power supplies 726, one or more wired or wireless network interfaces 750, one or more input and output interfaces 758, and / or one or more operating systems 741, such as Windows Server 2000. TM , Mac OS X TM , UnixTM Linux TM FreeBSD TM and so on.
[0152] In this embodiment, the method provided in the various optional implementations of the above embodiments can be executed by the central processor 722 in the server 700.
[0153] The computer device provided in the embodiments of the present application can also be a terminal. Referring to Figure 8 , Figure 8 is a structural diagram of a terminal provided in the embodiments of the present application. Taking a smart phone as an example, the smart phone includes a radio frequency (RF) circuit 810, a memory 820, an input unit 830, a display unit 840, a sensor 850, an audio circuit 860, a wireless fidelity (WiFi) module 870, a processor 880, and a power supply 890, and the like. The input unit 830 can include a touch panel 831 and other input devices 832, and the display unit 840 can include a display panel 841. The audio circuit 860 can include a speaker 861 and a microphone 862. Those skilled in the art can understand that Figure 8 The structure of the smart phone shown in the embodiments of the present application is not limited to the smart phone, and can include more or less components than the diagram, or combine some components, or different component arrangements.
[0154] The memory 820 can be used to store software programs and modules, and the processor 880 executes various function applications and data processing of the smart phone by running the software programs and modules stored in the memory 820. The memory 820 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), and the like; and the data storage area can store data created according to the use of the smart phone (such as audio data, a phone book, etc.), and the like. In addition, the memory 820 can include a high-speed random access memory, and can also include a non-volatile memory, for example, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.
[0155] The processor 880 is the control center of the smartphone, connecting all parts of the smartphone through various interfaces and lines, executing various functions of the smartphone and processing data by running or executing software programs and / or modules stored in the memory 820 and calling data stored in the memory 820. Optionally, the processor 880 can include one or more processing units; preferably, the processor 880 can integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface and application programs, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 880.
[0156] In the embodiment, the processor 880 in the smartphone can execute the method provided in various optional implementation manners of the above-mentioned embodiments.
[0157] According to an aspect of the present application, a computer readable storage medium is provided, the computer readable storage medium is used to store a computer program, when the computer program is run on a computer device, the computer program causes the computer device to execute the method provided in various optional implementation manners of the above-mentioned embodiments.
[0158] According to an aspect of the present application, a computer program product is provided, the computer program product includes a computer program stored in a computer readable storage medium. The processor of the computer device reads the computer program from the computer readable storage medium, and the processor executes the computer program, so that the computer device executes the method provided in various optional implementation manners of the above-mentioned embodiments.
[0159] The description of the flow or structure corresponding to each of the above-mentioned figures has its own emphasis, and the part not described in detail in a certain flow or structure can refer to the related description of other flows or structures.
[0160] The terms "first", "second", and the like in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0161] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0162] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0163] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can be physically present separately, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0164] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a RAM, a magnetic disk or an optical disk, and various computer program storage media.
[0165] The above embodiments are merely used to describe the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or make equivalent replacements for some technical features; and these modifications or replacements do not cause the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.
Claims
1. A method for processing containers based on edge cloud, characterized in that, The method is executed by an edge device, and the method comprises: receiving, by an interface plug-in of a container runtime, a container reconstruction request sent by a central management system; the container reconstruction request carries a first container identifier; if the first container identifier belongs to a container identifier set, performing, by the interface plug-in, container reconstruction on a container corresponding to the first container identifier according to the container reconstruction request, to obtain a first reconstruction result; the container identifier set is used to indicate containers that are authorized to be reconstructed on the edge device in a limited manner; if the first container identifier does not belong to the container identifier set, intercepting, by the interface plug-in, the container reconstruction request.
2. The method of claim 1, wherein, The method further comprises: if a first recycling request for a target container identifier in the container identifier set is received, marking, according to the first recycling request, the target container identifier in the container identifier set, to obtain a target container identifier after recycling marking; the first recycling request is generated by the central management system when the use time of the target container identifier in the container identifier set is a first recycling time; if the first container identifier is the target container identifier after recycling marking, intercepting, by the interface plug-in, the container reconstruction request.
3. The method of claim 1, wherein, The method further comprises:
4. The method of claim 1, wherein, obtaining a process termination signal between a first process and a second process; the process termination signal carries an inter-process container identifier; if the inter-process container identifier belongs to an inter-process identifier set and the inter-process container identifier comprises a second container identifier, performing, according to the process termination signal, container reconstruction on a container corresponding to the second container identifier, to obtain a second reconstruction result; the inter-process identifier set is used to indicate source processes and destination processes that are authorized to be terminated and containers that are authorized to be reconstructed on the edge device in a limited manner; if the inter-process container identifier does not belong to the inter-process identifier set, intercepting the process termination signal.
5. The method of claim 1, wherein, if the first process and the second process are different device processes in the same device, the inter-process container identifier comprises a process identifier of the first process and a process identifier of the second process; if the first process is a device process and the second process is a container process, the inter-process container identifier comprises the process identifier of the first process, the process identifier of the second process, and the second container identifier; if the first process and the second process are different processes in the same namespace in a container, the inter-process container identifier comprises the process identifier of the first process, the process identifier of the second process, and the second container identifier. 6. The method of claim 5, wherein, 7. The method of claim 5, wherein, The inter-process identifier set includes one or more of a limited-authority-deleted container group identifier, a limited-authority-changed container group identifier, and a limited-authority-changed container identifier on the edge device.
8. The method of claim 5, wherein, The obtaining step of the inter-process identifier set includes: acquiring a release indicator of a process termination signal on the edge device; sending the release indicator to the central management system; if the release indicator is less than or equal to an indicator threshold, receiving the inter-process identifier set sent by the central management system.
9. The method of claim 5, wherein, The method further includes: if the first process and the second process are different processes in a container under the same control group, performing container reconstruction on a container corresponding to a second container identifier in the inter-process container identifier according to the process termination signal, to obtain a second reconstruction result.
10. The method of claim 5, wherein, The method further includes: if a second recovery request for a target inter-process identifier in the inter-process identifier set is received from the central management system, recovering the target inter-process identifier from the inter-process identifier set according to the second recovery request; the second recovery request is generated by the central management system when the usage time of the target inter-process identifier in the inter-process identifier set is a second recovery time.
11. The method of claim 5, wherein, The method further includes: if the inter-process container identifier belongs to the inter-process identifier set and a container identifier in the inter-process container identifier is empty, releasing the process termination signal.
12. An edge cloud based container processing apparatus, comprising: The device deployed on an edge device includes a receiving unit, a reconstruction unit, and an intercepting unit. The receiving unit is configured to receive a container reconstruction request sent by a central management system through an interface plug-in of a container runtime; the container reconstruction request carries a first container identifier. The reconstruction unit is configured to, if the first container identifier belongs to a container identifier set, perform container reconstruction on a container corresponding to the first container identifier according to the container reconstruction request through the interface plug-in, to obtain a first reconstruction result; the container identifier set is used to indicate containers that are limited to be reconstructed on the edge device. The intercepting unit is configured to, if the first container identifier does not belong to the container identifier set, intercept the container reconstruction request through the interface plug-in.
13. A computer device, comprising: The computer device includes a processor and a memory: The memory is configured to store a computer program and transmit the computer program to the processor; The processor is configured to execute the method according to the instructions in the computer program.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium is configured to store a computer program, which, when executed on a computer device, causes the computer device to execute the method according to any one of claims 1-11.
15. A computer program product comprising a computer program, characterized in that, The computer program, when executed on a computer device, causes the computer device to execute the method according to any one of claims 1-11.
Citation Information
Cited By
Signal processing method and device, electronic equipment, storage medium and computer program product
CN122064456A