Database instance isolation method and system and host machine
By configuring isolation components and mounting private network elastic network interface cards in the cloud computing environment, the security isolation problem of different tenant database instances on the same host machine is solved, achieving both security isolation and improved resource utilization.
Patent Information
- Application Number
- CN202410638544.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-21
- Publication Date
- 2025-11-21
AI Technical Summary
In cloud computing environments, deploying database instances of different tenants on the same host machine presents security issues, including database kernel security, management component security, third-party plugin security, and weak isolation. This allows attackers to compromise database instances and affect the security and stability of other tenants.
By configuring isolation components in each resource object, resource management and interaction management are achieved, and elastic network interface cards in the target private network are mounted to achieve isolation between the operating environment and the communication network, ensuring secure isolation between database instances of different tenants.
This achieves secure isolation at the network and runtime environments layers between database instances of different tenants on the same host machine, avoiding the impact of intrusions and failures, ensuring the security of tenant database instances, and improving the utilization of cloud computing resources while reducing costs.
Smart Images

Figure CN121000402A_ABST
Abstract
Description
Technical Field
[0001] The embodiments in this specification relate to the field of computer technology, and in particular to database instance isolation methods, systems, and host machines. Background Technology
[0002] With the development of cloud computing technology, cloud service providers enable tenants to access dynamically scalable virtual resources via the internet. Cloud computing services pool a large number of network-connected computing resources, allowing tenants to obtain the resources and services they need on demand and in a scalable manner. However, to improve resource utilization and reduce costs, most cloud service providers deploy cloud database instances for different tenants on the same host machine. This deployment presents numerous security challenges, such as database kernel security, management component security, and third-party plugin security. These issues negatively impact the tenant experience of using cloud computing services. Therefore, an effective solution is urgently needed to address these problems. Summary of the Invention
[0003] In view of this, embodiments of this specification provide a database instance isolation method. One or more embodiments of this specification also relate to a database instance isolation system, a host machine, a computer-readable storage medium, and a computer program product, to address the technical deficiencies existing in the prior art.
[0004] According to a first aspect of the embodiments of this specification, a database instance isolation method is provided, applied to a host machine, wherein at least two resource objects running database instances are deployed on the host machine, and the database instances running in the at least two resource objects belong to different tenants; each resource object is configured with an isolation component, wherein the isolation component is used for resource management and interaction management of the resource objects, thereby isolating the running environments between the various resource objects through the resource management and interaction management; each resource object is also mounted with a target elastic network interface card in a target private network associated with the target tenant, wherein the communication network between the various resource objects is isolated by mounting the target elastic network interface card in the target private network.
[0005] According to a second aspect of the embodiments of this specification, a database instance isolation system is provided, including a host machine and at least two resource objects deployed on the host machine, wherein each resource object runs a database instance, and the database instances running in the at least two resource objects belong to different tenants; each resource object is configured with an isolation component, wherein the isolation component is used for resource management and interaction management of the resource objects, thereby isolating the running environments between the various resource objects through the resource management and interaction management; each resource object is also mounted with a target elastic network interface card in a target private network associated with a target tenant, wherein the communication network between the various resource objects is isolated by mounting the target elastic network interface card in the target private network.
[0006] According to a third aspect of the embodiments of this specification, a host machine is provided, comprising:
[0007] Memory and processor;
[0008] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the above-described database instance isolation method.
[0009] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions that, when executed by a processor, implement the steps of the database instance isolation method described above.
[0010] According to a fifth aspect of the embodiments of this specification, a computer program product is provided, including a computer program or instructions that, when executed by a processor, implement the steps of the database instance isolation method described above.
[0011] The database instance isolation method provided in this embodiment aims to isolate database instances corresponding to different tenants on the same host machine. An isolation component can be configured in the resource objects of the running database instances. This component enables resource management and interaction management of the resource objects, achieving runtime environment isolation between different resource objects on the same host machine. Furthermore, considering the need for network communication between different database instances, a target elastic network interface card (NIC) from the target private network associated with the target tenant can be attached to each resource object. This establishes communication network isolation between different resource objects on the same host machine. Thus, when deploying multiple tenant database instances on the same host machine, runtime environment isolation and communication network isolation achieve secure isolation at both the network and runtime layers, preventing intrusions at these layers and avoiding host-level failures caused by a single database instance anomaly. This ensures both improved cloud computing resource utilization and reduced costs while guaranteeing the security of tenant database instances. Attached Figure Description
[0012] Figure 1 This is a schematic diagram of a database instance isolation method provided in one embodiment of this specification;
[0013] Figure 2 This is a schematic diagram illustrating the deployment of resource objects in a database instance isolation method provided in one embodiment of this specification;
[0014] Figure 3 This is a schematic diagram of the structure of a database instance isolation system provided in one embodiment of this specification;
[0015] Figure 4 This is a structural block diagram of a host machine provided in one embodiment of this specification. Detailed Implementation
[0016] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0017] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0018] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0019] Furthermore, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0020] First, the terms and concepts used in one or more embodiments of this specification will be explained.
[0021] An Elastic Network Interface (ENI) is a virtual network interface card that provides elastic networking capabilities to elastic cloud servers. It is implemented based on virtualization technology, using virtualized hardware devices (such as virtual switches) to simulate a physical network environment. When a user creates an ENI, the cloud server assigns it a virtual network interface and connects it to the physical network.
[0022] VPC (Virtual Private Cloud) is a cloud service provided by cloud computing providers. Users can build their own private network within a network environment constructed by the provider, utilizing cloud resources. Within this private network, users can freely define the network topology, including network segmentation, IP address allocation, routing settings, and security group policies. They can also access the public cloud via VPN, dedicated lines, and other methods to achieve interconnectivity with data center resources.
[0023] Kubernetes, or K8s for short, is an open-source container orchestration system for automating the deployment, scaling, and management of containerized applications. It provides a powerful way to manage container clusters by using a series of control loops to ensure that the declared container state matches the actual state.
[0024] This specification provides a database instance isolation method, and also relates to a database instance isolation system, a host machine, a computer-readable storage medium, and a computer program product, which are described in detail in the following embodiments.
[0025] See Figure 1 , Figure 1 The diagram illustrates a database instance isolation method according to an embodiment of this specification. The method is applied to a host machine, on which at least two resource objects running database instances are deployed, and the database instances running in the at least two resource objects belong to different tenants. Each resource object is configured with an isolation component, which is used for resource management and interaction management of the resource objects, thereby isolating the operating environments between the resource objects. Each resource object also has a target elastic network interface card (NIC) in a target private network associated with the target tenant mounted on it, thereby isolating the communication networks between the resource objects.
[0026] The database instance isolation method provided in this embodiment is applied to scenarios where at least two tenant-corresponding database instances run on the same host machine, and each tenant-corresponding database instance runs in a different resource object, thereby enabling the provision of database services to at least two tenants on the same host machine.
[0027] Specifically, a host machine refers to a host that provides cloud computing resources to a tenant in response to their cloud resource usage requests. It provides database instances to the tenant, i.e., provides database services to the tenant. A tenant refers to a user who uses cloud computing services. A resource object refers to the smallest unit that can be created and managed in the Kubernetes (K8s) system. It is also the smallest resource object model created or deployed by the user in the resource object model. It can be understood as a resource object running a containerized database instance on K8s. An isolation component refers to a component configured separately in different resource objects on the same host machine. This isolation component can independently manage the resources and interactions within its respective resource object, thereby creating runtime environment isolation between different resource objects on the same host machine to achieve secure isolation between database instances of different tenants. Resource management refers to the operations performed by the isolation component deployed in the resource object to manage the available resources (such as storage or computing resources) within that resource object. These operations include, but are not limited to, resource scheduling and allocation. Interaction management refers to the operations performed by the isolation component deployed in the resource object to manage the system calls associated with that resource object. Runtime environment isolation specifically refers to the isolation effect between different resource objects on the same host machine so that their runtime environments do not affect or interfere with each other, thereby achieving security isolation at the runtime environment level.
[0028] Accordingly, the target tenant specifically refers to the tenant corresponding to the database instance running on any resource object; the target private network specifically refers to the Virtual Private Cloud (VPC) applied for by the target tenant when renting cloud computing services. The target elastic network interface (ENI) is the elastic network interface (ENI) in the target private network. Since each database instance corresponds to one tenant, and each tenant's database instance runs within a resource object, by attaching the elastic network interface of the tenant's private network to each resource object, communication network isolation between different resource objects on the same host can be achieved through the elastic network interface in the private network. Specifically, communication network isolation refers to the isolation effect where the communication networks of different resource objects on the same host do not affect or interfere with each other, thereby achieving network layer security isolation.
[0029] In practice, to improve resource utilization and reduce costs, cloud service providers often deploy multiple tenant database instances on the same host machine. However, this deployment can introduce security issues, such as: database kernel security vulnerabilities: database kernel logic vulnerabilities can allow attackers to gain superuser accounts on the database instance, enabling them to perform all high-risk operations (such as custom command execution, file upload and download, etc.); management component security vulnerabilities: cloud service providers' management and maintenance containers need to share data with tenant database kernel containers, and some operations require privileged container execution. This allows attackers to exploit management code vulnerabilities to use the privileged management container as a springboard to infiltrate the host machine where the database instance resides, posing a risk to other tenant database instances on the host machine; and third-party plugin security vulnerabilities: host machine... Most supported third-party plugins are provided by third parties, and the quality of their code varies greatly. This allows attackers to exploit various plugin vulnerabilities to compromise database instances, enabling privilege escalation, escape attacks, and other malicious activities. There is also the issue of weak isolation: because database processes in different database instances share the host machine's OS kernel, an abnormality in one database process can affect the host machine's OS kernel, rendering all database instances on the host machine unusable, resulting in a wide-ranging impact. Finally, there is the problem of network connectivity between processes on the same host machine: different database instances on the same host machine can communicate with each other, and the database instances and the host machine can communicate with each other. Once an attacker compromises one database instance, they can access other database instances on the same host machine via the network, and even gain access to the cloud service provider's control network, posing a significant threat to all of the cloud service provider's tenants.
[0030] Therefore, to achieve isolation between database instances corresponding to different tenants on the same host machine, an isolation component can be configured in the resource objects running the database instances. This allows for resource management and interaction management of the respective resource objects, thus creating runtime environment isolation between different resource objects on the same host machine. Furthermore, considering that different database instances also need to communicate over the network, a target elastic network interface card (NIC) from the target private network associated with the target tenant can be attached to each resource object. This enables communication network isolation between different resource objects on the same host machine.
[0031] like Figure 2As shown, the database instance isolation method provided in this embodiment can achieve exclusive OS kernel access for different resource objects on the same host machine through isolation components. It also enables OS kernel isolation between different database instances on the same host machine, and between database instances and the host machine. This eliminates problems such as escape attacks, process interference, and insufficient isolation capabilities caused by OS sharing. Furthermore, by individually mounting elastic network cards in the corresponding user's private cloud network for each resource object on the same host machine, the network isolation capabilities between different private cloud networks can achieve secure network layer isolation between database instances of different tenants on the same host machine, as well as secure network layer isolation between database instances and the host machine. This ensures that even if a single database instance is compromised, it cannot intrude into other tenant database instances or the cloud computing service provider's management network through the network layer.
[0032] For example, a cloud service provider offers cloud computing services to tenants A and B. To improve cloud resource utilization and reduce costs, the database instances of tenants A and B are deployed on the same host machine. Specifically, the database instance corresponding to tenant A, running on host machine A, is deployed in Kubernetes Pod_1, and the database instance corresponding to tenant B, also running on host machine A, is deployed in Kubernetes Pod_2. To ensure isolation between the database instances corresponding to tenants A and B, isolation components can be configured in Kubernetes Pod_1 and Kubernetes Pod_2 respectively. These isolation components manage the resources and interactions within their respective Pods independently, achieving runtime environment isolation between Kubernetes Pod_1 and Kubernetes Pod_2. Simultaneously, Kubernetes Pod_1 will also mount the elastic network interface ENI_1 from the private cloud network corresponding to tenant A, and Kubernetes Pod_2 will also mount the elastic network interface ENI_2 from the private cloud network corresponding to tenant B, thereby achieving communication network isolation between Kubernetes Pod_1 and Kubernetes Pod_2.
[0033] In summary, when deploying multiple tenant database instances on the same host machine, by isolating the runtime environment and communication network, secure isolation can be achieved between the database instances of different tenants at the network layer and runtime environment layer. This avoids intrusions at the runtime environment layer and network layer, and also prevents host machine-level failures caused by the anomaly of a single database instance. This ensures the security of tenant database instances while improving the utilization of cloud computing resources and reducing costs.
[0034] Furthermore, to ensure complete isolation of the database instances running within each resource object, multi-dimensional management operations can be performed through isolation components configured in each resource object. In this embodiment, the database resource of any one of the at least two resource objects is managed by the target isolation component configured for that target resource object; the system call tasks of the target resource object are executed through the target isolation component; and abnormal access requests of the target resource object are intercepted through the target isolation component. The target isolation component makes the database resource invisible to the host machine and its associated resource objects among the at least two resource objects.
[0035] Specifically, a target resource object refers to any one of at least two resource objects running on the same host machine. A target isolation component refers to the isolation component configured for the target resource object. Database resources refer to the resources of all associated database instances within the target resource object, including but not limited to computing resources, storage resources, and network resources. System call tasks refer to the system call responses of associated database instances within the target resource object. Abnormal access requests refer to attacks or other requests triggered against the target resource object.
[0036] Therefore, in order to ensure that database instances running in different resource objects on the same host machine can be securely isolated from each other, for any one of the at least two resource objects, the database resources of the target resource object can be managed through the target isolation resource configured for that target resource object, and the system call tasks of the target resource object can be executed. At the same time, abnormal access requests can be intercepted. In this way, the resource objects can be made invisible to each other through isolation resources, and at the same time, the resource objects can be made invisible to the host machine, thereby achieving the purpose of secure isolation.
[0037] In practical applications, isolation components can be implemented using sandbox kernel virtualization technology. This technology redirects files generated and modified by a program to its own folder. When a program attempts to function, security software can first allow it to run in the sandbox. If malicious behavior is detected, the program's further execution is prohibited, without causing any harm to the system. Sandboxing can also logically isolate processes. Programs executing in the sandbox do not actually modify or prevent modifications to system data, such as the registry or hard drive data. This achieves secure isolation between different database instances on the same host machine.
[0038] like Figure 2As shown, in practical implementation, for secure isolation of different database instances on the same host machine, the Sandbox kernel can be used as a security boundary between the resource object Pod and the host machine. All resources (compute, storage, network) within the resource object Pod can be managed by the Sandbox kernel, and all system calls within the resource object Pod are responded to by the Sandbox kernel. All attacks on the operating system within the resource object Pod will be intercepted by the Sandbox kernel. Simultaneously, the existence of the Sandbox kernel makes all resources within the resource object Pod invisible to the host machine and also invisible to other Kubernetes Pods on the same host machine. The Sandbox kernel achieves strong secure isolation between different Kubernetes Pods on the same host machine and between the Kubernetes Pod and the host machine. For example, for tenants A and B, corresponding to Kubernetes Pod_1 and Kubernetes Pod_2 respectively, a Sandbox kernel can be configured in Kubernetes Pod_1 and Kubernetes Pod_2 to achieve the above-mentioned resource management and interaction management objectives, ensuring the security of secure isolation.
[0039] In summary, by using isolation components for interaction and resource management, it is ensured that all resources and interactions within resource objects must be completed through the isolation components, thereby guaranteeing secure isolation between different database instances on the same host machine and achieving the goal of runtime environment isolation.
[0040] Furthermore, considering that the purpose of security isolation is to prevent attackers from simultaneously affecting database instances of different tenants on the same host machine, data storage space isolation can also be implemented to achieve complete isolation. In this embodiment, each of the at least two resource objects is also configured with data storage space, wherein the data storage space configured for each resource object is determined according to the tenant's rental request, and the storage space between the various resource objects is isolated by configuring data storage space for each resource object.
[0041] Specifically, data storage space refers to the data disk allocated to each resource object according to the rental needs of the tenant to which that resource object belongs. For example, if a tenant purchases 1TB of storage resources, then 1TB of data storage space will be allocated to the resource object running that tenant's database instance to support the tenant's use. Storage space isolation refers to the isolation effect between the data storage spaces used by different resource objects on the same host machine, ensuring that they do not affect or interfere with each other. That is, each resource object can only access its own corresponding data storage space, and the data storage spaces of other resource objects are not allowed to be accessed.
[0042] Therefore, in order to achieve complete isolation between different resource objects on the same host machine, the data storage space configured for each resource object will be determined according to the tenant's rental request, and the data storage space configured for each resource object will be exclusively used by the resource object to which it belongs, thereby achieving data storage space isolation.
[0043] like Figure 2 As shown, in practical applications, for any resource object Pod on the same host machine, it is necessary to ensure that each resource object Pod has an Elastic Network Interface (ENI) of a tenant's private network (VPC), and that each resource object Pod has exactly one ENI of a tenant's private network (VPC). Since the networks of different tenant private networks (VPCs) are isolated from each other, this ensures secure network layer isolation between different Kubernetes Pods on the same host machine, and between the Kubernetes Pod and the host machine. Simultaneously, each resource object Pod has its own dedicated data disk. By ensuring that each resource object Pod on the host machine has its own dedicated data disk, secure storage isolation can be achieved. For example, for Kubernetes Pod_1 and Kubernetes Pod_2 corresponding to tenants A and B respectively, Kubernetes Pod_1 and Kubernetes Pod_2 can each exclusively use the storage resources of the surfaces constructed by tenants A and B, respectively, achieving secure storage isolation.
[0044] In summary, by implementing secure isolation at the storage layer, it can be ensured that the storage space of different database instances on the same host cannot be accessed by each other. This ensures the security of the data storage space of other tenants even if one database instance is attacked.
[0045] Furthermore, to manage the database processes corresponding to the database instances, a monitoring user process can be configured for each resource object. In this embodiment, each of the at least two resource objects is also configured with a supervisory user process, which is used as the priority process of the resource object to manage the database processes corresponding to the database instances running in the resource object.
[0046] Specifically, the supervisory user process refers to the process that provides database process management functions for resource objects, which can be implemented using supervisord. Therefore, in order to manage the database processes corresponding to different database instances on the host machine, a supervisory user process can be configured for each of at least two resource objects, serving as the priority process for that resource object. This supervisory user process provides the resource object with the function of managing its database processes, thereby supporting database process management operations.
[0047] like Figure 2As shown, in practical applications, supervisord can be used as the highest priority process in the resource object Pod to occupy the Pod's resources (equivalent to the init process in a Linux system); creating a database instance involves first starting the resource object Pod, and then performing subsequent management operations (equivalent to starting a virtual machine first); all operations on the database instance only operate on the database process in the resource object Pod, without directly operating on the resource object Pod (equivalent to only operating on processes in a virtual machine); thus, it is possible to manage the database process through supervisord, such as automatically restarting the database process after a crash.
[0048] In summary, by using the supervisory user process as the highest priority process to occupy the resources of the resource object, it is possible to manage the database process using the supervisory user process, thereby ensuring the normal operation of other capabilities under the premise of security isolation.
[0049] Furthermore, considering that the cloud computing resources corresponding to the database instance are resources provided to tenants by cloud service providers, in order to ensure that the management capabilities of cloud service providers are not affected by security isolation, operation and maintenance containers can be configured for resource objects through custom resource information to achieve management purposes. In this embodiment, operation and maintenance containers are configured for each of the at least two resource objects through custom resource information in the baseline extension component. The operation and maintenance containers are used to execute operation and maintenance tasks of associated resource objects and operate the database processes of associated resource objects, as well as to call the target elastic network interface card in the resource object to communicate with the service node in the target private network. The operation and maintenance containers are also used to mount the storage volume of the resource object for reading and writing target data in the storage volume.
[0050] Specifically, the baseline extension component refers to the extended function component configured for the host machine. Through the baseline extension component, the functionality of the host machine can be extended, and the extended functions can be set according to actual needs; this embodiment does not impose any limitations. In practical applications, the baseline extension component can be implemented using the Kubernetes enhancement suite OpenKruise. Custom resource information specifically refers to resource information configured according to actual needs. Its configuration content determines the functions added to the resource object. For example, operation and maintenance operations can be configured with relevant information about operation and maintenance operations in the custom resource information. The operation and maintenance container is a container used to run operation and maintenance operations. It can execute operation and maintenance tasks of associated resource objects and operate the database processes of associated resource objects. It can also communicate with the target elastic network interface card in the resource object and the service nodes in the target private network. In addition, the operation and maintenance container can also be used to mount storage volumes, enabling the host machine to read and write data in the storage volume.
[0051] Based on this, to ensure that the management of cloud service providers is not affected by security isolation, an operation and maintenance (O&M) container can be configured for each of at least two resource objects using custom resource information in the baseline extension component. This allows the O&M container to execute O&M tasks and operate the database processes of associated resource objects. This not only achieves O&M objectives but also enables manipulation of the database processes of resource objects. Furthermore, the O&M container can communicate with service nodes in the target private network via the target elastic network interface card (NIC) of the resource object, achieving network layer management. In addition, the O&M container can mount storage volumes of resource objects to read and write target data within those volumes. This supports management of any resource object on the host machine from the resource, interaction, and network levels, ensuring that management privileges remain intact while maintaining security isolation.
[0052] like Figure 2 As shown, in practical applications, ephemeral containers can be injected into resource object Pods using the custom resource EphemeralJob under the Kubernetes enhancement suite OpenKruise to perform operation and maintenance operations. Since the ephemeral container shares the PID namespace of the engine container in the resource object Pod, it can directly operate the database process. Because the ephemeral container is located in the sandbox network namespace of the resource object Pod, it can directly use the elastic network interface (ENI) in the tenant's private network VPC to communicate with services within the user's tenant's private network VPC. At the same time, the ephemeral container can also use VolumeMounts to mount volumes in the resource object Pod, allowing the ephemeral container to mount cloud disks in the resource object Pod through VolumeMounts, thereby enabling the ephemeral container to read and write data on the cloud disks and thus manage user database instances.
[0053] An ephemeral container is a special type of container that differs from a regular container. Ephemeral containers lack guarantees regarding resources or execution and do not automatically restart, making them unsuitable for building applications. While the same Container.Spec fields are used when describing ephemeral containers as regular containers, many fields are not allowed. For example, ephemeral containers lack port configuration, so fields like `ports`, `livenessProbe`, and `readinessProbe` are not permitted. Furthermore, since Pod resource allocation is immutable, `resources` configuration is also not allowed. VolumeMounts are used to mount volumes to specific paths within a container. This allows the container to access and use data within the volume, enabling persistent data storage.
[0054] In summary, by configuring an operations and maintenance container in each resource object, cloud service providers can still maintain the ability to operate and manage database instances, thereby ensuring that cloud services can provide stable and secure services to tenants and protect their rights.
[0055] Furthermore, to support the ability to read and write files, execute commands, and exchange data within resource objects on the host machine, an access container can be deployed on the host machine. In this embodiment, the host machine is also configured with a host machine access container, which provides each of the at least two resource objects with the functions of reading and writing files on the host machine, executing commands on the host machine, and exchanging data on the host machine.
[0056] Specifically, a host access container refers to an access container installed on the host machine. This access container enables functions such as file reading and writing, data interaction, and command execution for each resource object on the host machine. In other words, by configuring a host access container on the host machine, it can provide each of at least two resource objects with the ability to read and write files, execute commands, and exchange data on the host machine.
[0057] Specifically, the file reading and writing function on the host machine refers to the function of reading and writing data in the cloud disk, such as reading data in the cloud disk or cgroup files; the command execution function on the host machine refers to the function of triggering the execution of commands on the resource object on the host machine. It should be noted that triggering commands on the host machine needs to be executed in the isolation component; and the data interaction function on the host machine refers to the function of data interaction between the processes on the host machine and the resource object.
[0058] In summary, by configuring a host access container on the host machine, it is possible to read and write files, execute commands, and exchange data with respect to each resource object on the host machine, thereby enabling the management of database instances on the host machine.
[0059] Furthermore, to achieve the purpose of managing and controlling the database instances on the host machine, a resource object management node can be configured on the host machine. In this embodiment, the host machine is also configured with a resource object management node, and the data disk directory and database kernel container directory of each of the at least two resource objects are mapped to the host machine directory of the host machine; the log data and performance data of the database instances running on each resource object are collected by accessing the host machine directory through the resource object management node.
[0060] Based on this, considering that instance operation and maintenance tasks are the foundation for maintaining stable cloud computing resources, in order to ensure stable service to tenants, the resource object management node can also be used to perform one-way access to the database instance running on each resource object, wherein the one-way access is used to execute instance operation and maintenance tasks for the database instance running on each resource object.
[0061] Specifically, the resource object management node refers to a node deployed on the host machine that manages all resource objects. This node allows for the collection of log and performance data from the database instances running within those resource objects. This data can then be used to optimize the database instances during the operation and maintenance phase. The data disk directory and database kernel container directory are directories associated with the resource objects, while the host machine directory is a directory associated with the host machine. By mapping directories associated with resource objects to host machine directories, the resource object management node can access these directories to collect relevant data. Correspondingly, instance operation and maintenance tasks refer to the tasks performed by the host machine when maintaining the database instance.
[0062] Based on this, to achieve the goal of database instance management, a resource object management node can be configured on the host machine. By mapping the data disk directory and database kernel container directory of each of at least two resource objects to the host machine's directory, the resource object management node can access the host machine directory during the management phase. This allows for the collection of log and performance data of the database instances running on each resource object, thereby achieving the goal of managing the database instances running on the resource objects. Furthermore, the resource management node can also perform one-way access to the database instances running on each resource object. Since the host machine needs to access the resource object Pods, but for security reasons, the resource object Pods cannot access the host machine, one-way access prevents insecure Pods corresponding to the tenant's database instance from breaching the security boundary to access the secure and trusted environment (the host machine environment), thus preventing Pods from breaching the security boundary.
[0063] like Figure 2 As shown, in practical applications, for all resource object Pods on the host machine, ServiceAPI+GOKU technology can provide resource object Pods with the following capabilities: reading and writing files (data in cloud disks, cgroup files, / proc, etc.) in the resource object Pods on the host machine; triggering the execution of commands in the resource object Pods on the host machine (triggering commands to be executed in the sandbox kernel on the host machine); and data interaction (socket, shared memory, pipe, etc.) between the processes on the host machine and the resource object Pods.
[0064] Furthermore, regarding the management of database instances on the host machine, firstly, the data disk directory in the resource object Pod and the cgroup directory of the database kernel container can be securely mapped to the host machine's directory via the Service API. The resource object management node on the host machine can directly read and write the contents mapped to the host machine's directory, thereby enabling the collection of log data and performance data of the database instance. Secondly, the lite-linker function provided by the container service can enable one-way access from the resource object management node on the host machine to the database instance. This prevents insecure Pods corresponding to the tenant's database instance from breaching the security boundary to access the secure and trusted environment (the host machine environment), thus achieving the goal of preventing Pods from breaching the security boundary.
[0065] In practical implementation, when using the lite-linker function provided by the container service to enable one-way access from the resource object management node on the host machine to the database instance, the lite-linker technology is actually based on virtual network interface pair (vethpair) technology: First, a veth1 network interface pair is created in the resource object Pod and assigned an IP address of a specific network segment, while a veth2 network interface pair is created on the host machine and assigned an IP address of a specific network segment. Second, by configuring routing rules on the host machine, all traffic accessing IP address 1 on the host machine is forwarded to veth1 via veth2, thus enabling access from the host machine to the resource object Pod. At the same time, by configuring veth2 through the host machine's routing rules to intercept all inbound traffic forwarded by veth1, the resource object Pod cannot access services on the host machine, thereby achieving one-way access from the host machine to the resource object Pod.
[0066] In summary, by configuring a resource object management node on the host machine, the resource object management node can manage and control the database instances running on the host machine. Furthermore, by configuring corresponding functional services, it is possible to achieve one-way access to the database instances, thereby providing tenants with stable and secure cloud computing services and preventing resource objects from breaching security boundaries to access the host machine.
[0067] Furthermore, to enable effective management of global resources and containers on the host machine, a host kernel and a host agent program can be configured on the host machine. In this embodiment, the host machine is also configured with a host kernel and a host agent program, wherein the host kernel is used to manage the global resources of the host machine, and the host agent program is used to configure container management functions for the host machine.
[0068] Specifically, the host kernel refers to the host machine's OS kernel, and the host agent program refers to the program that manages containers on the host machine. In other words, the host machine is also configured with a host kernel and a host agent program. The host kernel can manage the global resources of the host machine, and the host agent program can configure container management functions on the host machine to manage containers.
[0069] like Figure 2As shown, in practical applications where the database instance is deployed on a host machine, all resources (compute, storage, and network) on the host machine can be managed through the host kernel. Furthermore, since the host machine is connected to a network interface card within a large account private network (VPC), it is within the VPC's control network. Therefore, the resource object management nodes and host agents on the host machine can communicate with the central management service. The host agents are primarily responsible for managing the lifecycle of the container management cluster, resource objects, and resource object management nodes on the host machine.
[0070] In summary, by providing dedicated isolation components (sandbox kernels) for each resource object Pod on the host machine, fault domains can be controlled within a secure sandbox, thereby preventing host-level failures caused by the anomaly of a single resource object Pod. Furthermore, by providing customization capabilities for different isolation components (sandbox kernels) at the operating system level, such as sysctl configurations, personalized system configurations can be achieved for different resource object Pods on the same host machine. For example, different Pods can set customized sysctl.conf operating system kernel parameters according to their own services, and configure transparent bigpage policies that suit their specific services.
[0071] The database instance isolation method provided in this embodiment aims to isolate database instances corresponding to different tenants on the same host machine. An isolation component can be configured in the resource objects of the running database instances. This component enables resource management and interaction management of the resource objects, achieving runtime environment isolation between different resource objects on the same host machine. Furthermore, considering the need for network communication between different database instances, a target elastic network interface card (NIC) from the target private network associated with the target tenant can be attached to each resource object. This establishes communication network isolation between different resource objects on the same host machine. Thus, when deploying multiple tenant database instances on the same host machine, runtime environment isolation and communication network isolation achieve secure isolation at both the network and runtime layers, preventing intrusions at these layers and avoiding host-level failures caused by a single database instance anomaly. This ensures both improved cloud computing resource utilization and reduced costs while guaranteeing the security of tenant database instances.
[0072] Corresponding to the above method embodiments, this specification also provides embodiments of a database instance isolation system. Figure 3A schematic diagram of the structure of a database instance isolation system provided in one embodiment of this specification is shown. Figure 3 As shown, the database instance isolation system 300 includes a host machine 310 and at least two resource objects 320 deployed on the host machine. Each resource object runs a database instance, and the database instances running in the at least two resource objects belong to different tenants. Each resource object is configured with an isolation component, which is used for resource management and interaction management of the resource objects to isolate the running environments between the resource objects. Each resource object is also equipped with a target elastic network interface card (NIC) in a target private network associated with the target tenant, which isolates the communication networks between the resource objects.
[0073] In an optional embodiment, the database resource of any one of the at least two resource objects is managed by a target isolation component configured for the target resource object; the system call task of the target resource object is executed by the target isolation component; and abnormal access requests of the target resource object are intercepted by the target isolation component. The target isolation component makes the database resource invisible to the host machine and its associated resource objects among the at least two resource objects.
[0074] In an optional embodiment, each of the at least two resource objects is further configured with a data storage space, wherein the data storage space configured for each resource object is determined according to the tenant’s rental request, and the storage space between the various resource objects is isolated by configuring data storage space for each resource object.
[0075] In an optional embodiment, each of the at least two resource objects is further configured with a supervisory user process, which is used as the priority process of the resource object to manage the database process corresponding to the database instance running in the resource object.
[0076] In an optional embodiment, the system further includes configuring an operation and maintenance container for each of the at least two resource objects using custom resource information in the baseline extension component. The operation and maintenance container is used to execute operation and maintenance tasks of the associated resource object and operate the database process of the associated resource object, as well as to invoke the target elastic network interface card in the resource object to communicate with the service node in the target private network. The operation and maintenance container is also used to mount the storage volume of the resource object for reading and writing target data in the storage volume.
[0077] In an optional embodiment, the host machine is further configured with a host machine access container, which provides each of the at least two resource objects with functions for reading and writing files on the host machine, executing commands on the host machine, and exchanging data on the host machine.
[0078] In an optional embodiment, the host machine is further configured with a resource object management node, wherein the data disk directory and database kernel container directory of each of the at least two resource objects are mapped to the host machine directory of the host machine; the log data and performance data of the database instance running on each resource object are collected by accessing the host machine directory through the resource object management node.
[0079] In an optional embodiment, the resource object management node is further configured to perform one-way access to the database instance running on each resource object, wherein the one-way access is used to perform instance operation and maintenance tasks for the database instance running on each resource object.
[0080] In an optional embodiment, the host machine is further configured with a host machine kernel and a host machine agent program, wherein the host machine kernel is used to manage the global resources of the host machine, and the host machine agent program is used to configure container management functions for the host machine.
[0081] The database instance isolation system provided in this embodiment, in order to isolate database instances corresponding to different tenants on the same host machine, can configure isolation components in the resource objects of running database instances. This allows for resource management and interaction management of the resource objects, creating runtime environment isolation between different resource objects on the same host machine. Furthermore, considering that different database instances also need network communication, a target elastic network interface card (NIC) from the target private network associated with the target tenant can be attached to each resource object. This enables communication network isolation between different resource objects on the same host machine. Thus, when multiple tenant database instances are deployed on the same host machine, runtime environment isolation and communication network isolation achieve secure isolation at both the network and runtime layers, preventing intrusions at the runtime and network layers. This also prevents host-level failures caused by a single database instance anomaly, ensuring the security of tenant database instances while improving cloud computing resource utilization and reducing costs.
[0082] The above is an illustrative scheme of a database instance isolation system according to this embodiment. It should be noted that the technical solution of this database instance isolation system and the technical solution of the database instance isolation method described above belong to the same concept. For details not described in detail in the technical solution of the database instance isolation system, please refer to the description of the technical solution of the database instance isolation method described above.
[0083] Figure 4 A structural block diagram of a host machine 400 according to one embodiment of this specification is shown. The components of the host machine 400 include, but are not limited to, a memory 410 and a processor 420. The processor 420 is connected to the memory 410 via a bus 430, and a database 450 is used to store data.
[0084] The host 400 also includes an access device 440, which enables the host 400 to communicate via one or more networks 460. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 440 may include one or more of any type of wired or wireless network interface (e.g., a network interface controller (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.
[0085] In one embodiment of this specification, the aforementioned components of the host machine 400 and Figure 4 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 4 The host architecture diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0086] Host 400 can be any type of stationary or mobile host, including mobile computers (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable hosts (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary hosts such as desktop computers or personal computers (PCs). Host 400 can also be a mobile or stationary server.
[0087] The processor 420 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the database instance isolation method described above.
[0088] The above is an illustrative scheme of a host machine according to this embodiment. It should be noted that the technical solution of this host machine and the technical solution of the database instance isolation method described above belong to the same concept. For details not described in detail in the technical solution of the host machine, please refer to the description of the technical solution of the database instance isolation method described above.
[0089] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the database instance isolation method described above.
[0090] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium belongs to the same concept as the technical solution of the database instance isolation method described above. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the database instance isolation method described above.
[0091] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described database instance isolation method.
[0092] The above is an illustrative example of a computer program according to this embodiment. It should be noted that the technical solution of this computer program belongs to the same concept as the technical solution of the database instance isolation method described above. Details not described in detail in the computer program's technical solution can be found in the description of the technical solution of the database instance isolation method described above.
[0093] An embodiment of this specification also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the database instance isolation method described above.
[0094] The above is an illustrative scheme of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the database instance isolation method described above belong to the same concept. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the database instance isolation method described above.
[0095] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0096] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or certain intermediate forms. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added or removed according to the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.
[0097] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.
[0098] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0099] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A database instance isolation method, applied to a host machine, wherein at least two resource objects running database instances are deployed on the host machine, and the database instances running in the at least two resource objects belong to different tenants; each resource object is configured with an isolation component, wherein, The isolation component is used for resource management and interaction management of resource objects, thereby isolating the operating environments of each resource object through resource management and interaction management; each resource object is also equipped with a target elastic network interface card in the target private network associated with the target tenant, thereby isolating the communication networks of each resource object through the mounting of the target elastic network interface card in the target private network.
2. The database instance isolation method according to claim 1, wherein the database resource of any one of the at least two resource objects is managed by a target isolation component configured for the target resource object; the system call task of the target resource object is executed by the target isolation component; and abnormal access requests of the target resource object are intercepted by the target isolation component; wherein, The target isolation component makes the database resource invisible to the host machine and the associated resource object among the at least two resource objects.
3. The database instance isolation method according to claim 1, wherein each of the at least two resource objects is further configured with a data storage space, wherein, The data storage space configured for each resource object is determined based on the tenant's rental request, and the storage space between each resource object is isolated by configuring data storage space for each resource object.
4. The database instance isolation method according to claim 1, wherein each of the at least two resource objects is further configured with a supervisory user process, which is used as the priority process of the resource object to manage the database process corresponding to the database instance running in the resource object.
5. The database instance isolation method according to claim 1, further comprising: Configure an operation and maintenance container for each of the at least two resource objects using custom resource information in the baseline extension component. The operation and maintenance container is used to execute operation and maintenance tasks of the associated resource object and operate the database process of the associated resource object, as well as to call the target elastic network interface card in the resource object to communicate with the service node in the target private network. The operation and maintenance container is also used to mount the storage volume of the resource object for reading and writing target data in the storage volume.
6. The database instance isolation method according to claim 1, wherein the host machine is further configured with a host machine access container, the host machine access container providing each of the at least two resource objects with functions for reading and writing files on the host machine, executing commands on the host machine, and exchanging data on the host machine.
7. The database instance isolation method according to any one of claims 1-6, wherein the host machine is further configured with a resource object management node, and the data disk directory and database kernel container directory of each of the at least two resource objects are mapped to the host machine directory of the host machine; the log data and performance data of the database instance running on each resource object are collected by accessing the host machine directory through the resource object management node.
8. The database instance isolation method according to claim 7, wherein the resource object management node is further configured to perform one-way access to the database instance running on each resource object, wherein, The one-way access is used to perform instance operation and maintenance tasks for the database instance running on each resource object.
9. The database instance isolation method according to any one of claims 1-6, wherein the host machine is further configured with a host machine kernel and a host machine agent program, wherein, The host kernel is used to manage the global resources of the host machine, and the host agent is used to configure container management functions for the host machine.
10. A database instance isolation system, comprising a host machine and at least two resource objects deployed on the host machine, wherein, Each resource object runs a database instance, and the database instances running in at least two resource objects belong to different tenants; each resource object is configured with an isolation component, wherein the isolation component is used for resource management and interaction management of the resource object, thereby isolating the running environments between the various resource objects through the resource management and interaction management; each resource object is also mounted with a target elastic network interface card in the target private network associated with the target tenant, wherein the communication network between the various resource objects is isolated by mounting the target elastic network interface card in the target private network.
11. A host machine, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 9.
12. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 9.
13. A computer program product comprising a computer program or instructions which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 9.