A method and apparatus for assessing the health of a container
Patent Information
- Application Number
- CN202210017640.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-07
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-01-07
AI Technical Summary
[0003]现有技术采用探针方式并通过单一检测指标检测容器健康状态,检测结果为定性结果,只能够确定当前状态下容器是否存活,以及是否能对外提供服务等
[0041]The container health status assessment method and apparatus provided in this invention detect container safety indicators and container performance indicators according to a preset configured time period; generate corresponding first and second identifier numbers based on the first detection results of the container safety indicators and the second detection results of the container performance indicators; and determine container health status assessment parameters based on the first and second identifier numbers. This method can quantitatively obtain the container health status and helps to take countermeasures against the container health status in advance based on the container health reminder status and container health warning status.
Smart Images

Figure CN114356675B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and specifically to a method and apparatus for assessing the health status of containers. Background Technology
[0002] A container is essentially a group of processes running on a host machine, and it is widely used.
[0003] Current technologies use probes and single indicators to detect the health status of containers. The results are qualitative, only determining whether the container is currently alive and capable of providing services. Quantitative results are unavailable, and container anomalies are often only discovered after the fact, at which point the damage is irreversible. Summary of the Invention
[0004] To address the problems in the prior art, embodiments of the present invention provide a method and apparatus for assessing the health status of containers, which can at least partially solve the problems existing in the prior art.
[0005] On the one hand, this invention proposes a method for assessing the health status of a container, comprising:
[0006] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0007] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0008] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0009] The first identifier number is generated based on the first detection result of the container safety indicators, including:
[0010] If the first test results of all container safety indicators are normal, then the first identification number is determined to be the first type identification number;
[0011] If the first detection result of at least one container safety indicator is abnormal, then the first identification number is determined to be the second type identification number.
[0012] The second identifier number is generated based on the second test result of the container performance index, including:
[0013] If the second detection results of all container performance indicators are normal within the preset configuration time period, then the second identification number is determined to be the first type identification number;
[0014] If the second detection result of at least one container performance indicator is abnormal outside the preset configuration time period, then the second identification number is determined to be a third type identification number;
[0015] If the second detection result of at least one container performance indicator is abnormal within the preset configuration time period, then the second identification number is determined to be a fourth type identification number.
[0016] The step of determining the container health status assessment parameters based on the first identification number and the second identification number includes:
[0017] The container health status assessment parameters are determined based on the sum of the first identification number and the second identification number.
[0018] The step of determining the container health status assessment parameters based on the sum of the first identifier number and the second identifier number includes:
[0019] If the sum of the first identifier number and the second identifier number is the sum of the first type identifier number and the first type identifier number, then the container health status assessment parameter is determined to be the first type container health status assessment parameter.
[0020] If the sum of the first identifier number and the second identifier number is the sum of the first type identifier number and the third type identifier number, then the container health status assessment parameter is determined to be the second type container health status assessment parameter.
[0021] If the calculation process of the sum of the first identifier number and the second identifier number includes the second type identifier number and / or the fourth type identifier number, then the container health status assessment parameter is determined to be the third type container health status assessment parameter.
[0022] The step of detecting container performance metrics according to a preset configured time period includes:
[0023] Based on the preset configured time period, the cgroups subsystem is used to obtain container performance metrics and detect whether the container performance metrics are abnormal.
[0024] On one hand, the present invention proposes a container health status assessment device, comprising:
[0025] The detection unit is used to detect container safety indicators and container performance indicators according to a preset time period.
[0026] The generation unit is used to generate a first identification number and a second identification number corresponding to the first detection result of the container safety index and the second detection result of the container performance index.
[0027] The assessment unit is used to determine container health status assessment parameters for assessing the health status of the container based on the first identification number and the second identification number.
[0028] Specifically, the generation unit is used for:
[0029] If the first test results of all container safety indicators are normal, then the first identification number is determined to be a first type identification number; if the first test result of at least one container safety indicator is abnormal, then the first identification number is determined to be a second type identification number.
[0030] In another aspect, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a bus, wherein,
[0031] The processor and the memory communicate with each other via the bus;
[0032] The memory stores program instructions that can be executed by the processor, and the processor can execute the following methods by calling the program instructions:
[0033] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0034] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0035] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0036] This invention provides a non-transitory computer-readable storage medium, comprising:
[0037] The non-transitory computer-readable storage medium stores computer instructions that cause the computer to perform the following methods:
[0038] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0039] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0040] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0041] The container health status assessment method and apparatus provided in this invention detect container safety indicators and container performance indicators according to a preset configured time period; generate corresponding first and second identifier numbers based on the first detection results of the container safety indicators and the second detection results of the container performance indicators; and determine container health status assessment parameters based on the first and second identifier numbers. This method can quantitatively obtain the container health status and helps to take countermeasures against the container health status in advance based on the container health reminder status and container health warning status. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0043] Figure 1 This is a flowchart illustrating a container health status assessment method provided in an embodiment of the present invention.
[0044] Figure 2 This is a schematic diagram of the structure of a container health status assessment device provided in an embodiment of the present invention.
[0045] Figure 3 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments and descriptions of the present invention are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other.
[0047] Figure 1 This is a flowchart illustrating a container health status assessment method according to an embodiment of the present invention, as shown below. Figure 1 As shown, the container health status assessment method provided in this embodiment of the invention includes:
[0048] Step S1: Detect container security indicators and container performance indicators according to the preset configuration time period.
[0049] Step S2: Generate the corresponding first and second identification numbers based on the first detection results of the container safety indicators and the second detection results of the container performance indicators.
[0050] Step S3: Determine the container health status assessment parameters based on the first identification number and the second identification number.
[0051] In step S1 above, the device detects container safety indicators and container performance indicators according to a preset configuration time period. The device can be a computer device or similar equipment that executes this method. The preset configuration time period can be set independently according to actual conditions, and can be selected as 10 minutes, that is, the step of detecting container performance indicators is performed periodically every 10 minutes.
[0052] Typically, the preset configuration time period ti containing the current time is selected to perform the step of detecting container performance indicators. The preset configuration time periods before this (ti-1, ti-2...ti-m, etc.) are all preset configuration time periods outside the preset configuration time period ti.
[0053] The procedure of checking container safety indicators can also be performed periodically, without specific limitations.
[0054] Container security indicators can include detecting abnormal permissions, abnormal files, abnormal networks, and abnormal detection behavior, which are explained below:
[0055] Abnormal privilege detection: Set preset privilege escalation behavior characteristics in the privilege escalation whitelist. When the privilege escalation behavior characteristics of a container are detected to be inconsistent with the preset privilege escalation behavior characteristics, it is determined that the privilege is abnormal.
[0056] File anomaly detection: Set a preset file name in the file whitelist. When the container accesses a file whose name is not the preset file name, it will determine that the file is anomaly.
[0057] Detecting network anomalies: Set up a network anomaly behavior signature database. When a container's network access behavior is detected to match the behavior signature in the database, a network anomaly is determined.
[0058] Detecting Abnormal Behavior: A preset abnormal behavior combination feature library is established. When the detected combined behavior of a container matches the combined behavior features of the preset abnormal behavior combination feature library, the behavior is determined to be abnormal. That is, a single behavior in a combination cannot determine whether it is abnormal; combining these behaviors can determine whether they are abnormal. For example:
[0059] 1. Call the Docker API interface from within the container to query the running system container and image information.
[0060] 2. Execute Docker commands inside the container to run the container and obtain the Kubernetes API address and cluster key inside the container.
[0061] 3. Control the entire cluster by making Kubernetes HTTPS requests.
[0062] Kubernetes, or K8s for short, is an abbreviation formed by replacing the eight characters "ubernete" in its name. It is an open-source application used to manage containerized applications across multiple hosts in a cloud platform. Kubernetes aims to make deploying containerized applications simple and efficient, providing a mechanism for application deployment, planning, updating, and maintenance.
[0063] Container performance metrics include: detecting CPU anomalies, memory anomalies, network read / write anomalies, and disk usage anomalies, which are explained below:
[0064] Detect CPU anomalies: When the container's CPU usage is detected to be above 80% of its preset CPU quota, a CPU anomaly is determined.
[0065] Memory anomaly detection: When the container's memory usage exceeds 80% of its preset memory limit, a memory anomaly is identified.
[0066] Detect network read / write anomalies: When network traffic generated by a container exceeds 80% of the preset network traffic limit, a network read / write anomaly is identified.
[0067] Detect abnormal disk usage: When it is detected that the container's disk space usage exceeds 80% of the preset disk usage limit, it is determined that the disk usage is abnormal.
[0068] Furthermore, the step of detecting container performance metrics according to a preset configured time period includes:
[0069] Based on a preset time period, container performance metrics are obtained through the cgroups subsystem, and the system checks for anomalies in these metrics. The process of detecting anomalies in container performance metrics is explained in the above embodiments and will not be repeated here.
[0070] cgroups stands for control groups. cgroups defines a subsystem for each type of controllable resource. The subsystems relevant to the embodiments of this invention are described below:
[0071] The cpuacct subsystem reads CPU usage reports to obtain the container's CPU usage.
[0072] The memory subsystem obtains the container's memory usage.
[0073] The net_cls subsystem is used to obtain network traffic generated by containers.
[0074] The blkio subsystem is used to obtain the container's disk space usage.
[0075] You can also check whether a container is engaging in unauthorized behavior, such as accessing sensitive files and paths, through the cgroups subsystem device module.
[0076] In step S2 above, the device generates a first identification number and a second identification number respectively based on the first detection result of the container safety index and the second detection result of the container performance index.
[0077] Furthermore, a first identification number is generated based on the first detection result of the container safety indicators, including:
[0078] If the first detection result of all container security indicators is normal, then the first identifier number is determined to be the first type identifier number; referring to the above example, if the detection results of detection permissions, detection files, detection networks and detection behaviors are all normal, then the first identifier number is determined to be the first type identifier number 0.
[0079] If the first detection result of at least one container security indicator is abnormal, then the first identifier number is determined to be the second type identifier number. If the detection results of at least one of the detection permissions, detection files, detection networks, and detection behaviors are abnormal, then the first identifier number is determined to be the second type identifier number 4.
[0080] For container safety indicators, use 0 and 4 to represent them, where 0 is normal and 4 is abnormal.
[0081] Furthermore, a second identification number is generated based on the second test result of the container performance indicators, including:
[0082] If the second detection results of all container performance indicators are normal within the preset configuration time period, then the second identifier number is determined to be the first type identifier number; referring to the above example, if the detection results of detection permissions, detection files, detection networks and detection behaviors are all normal within the preset configuration time period, then the second identifier number is determined to be the first type identifier number 0.
[0083] If the second detection result of at least one container performance indicator is abnormal outside the preset configuration time period, then the second identifier number is determined to be a third type identifier number; if at least one of the detection results of detection permissions, detection files, detection networks, and detection behaviors is abnormal outside the preset configuration time period, then the second identifier number is determined to be a third type identifier number 1. The above explanation applies to the period outside the preset configuration time period, and will not be repeated here.
[0084] If the second detection result of at least one container performance indicator is abnormal within the preset configuration time period, then the second identifier number is determined to be the fourth type identifier number. If at least one of the detection results of detection permissions, detection files, detection networks, and detection behaviors is abnormal within the preset configuration time period, then the second identifier number is determined to be the fourth type identifier number 2.
[0085] Container performance metrics: Container performance is represented by three numbers: 0, 1, and 2. 0 indicates normal; 1 indicates an alert status, indicating that the container has experienced performance problems outside the preset configuration time period; and 2 indicates a warning status, indicating that the container has experienced performance problems within the preset configuration time period.
[0086] In step S3 above, the device determines container health status assessment parameters for assessing the health status of the container based on the first identification number and the second identification number.
[0087] Further, the step of determining the container health status assessment parameters based on the first identification number and the second identification number includes:
[0088] The container health status assessment parameters are determined based on the sum of the first identification number and the second identification number.
[0089] Further, determining the container health status assessment parameters based on the sum of the first identifier number and the second identifier number includes:
[0090] If the sum of the first identifier number and the second identifier number is equal to the sum of the first type identifier number and the first type identifier number, then the container health status assessment parameter is determined to be the first type container health status assessment parameter. Referring to the above example, if the sum of the first identifier number and the second identifier number is 0, it indicates that the container safety indicators and container performance indicators are normal, the first type container health status assessment parameter is 0, indicating that the container is healthy.
[0091] If the sum of the first identifier number and the second identifier number is the sum of the first type identifier number and the third type identifier number, then the container health status assessment parameter is determined to be the second type container health status assessment parameter. Referring to the above example, if the sum of the first identifier number and the second identifier number is 1, it means that the container safety indicators are normal, but the container performance indicators are in a warning state. The second type container health status assessment parameter is 1, indicating that the container needs attention.
[0092] If the calculation process of the sum of the first and second identifier numbers includes the second type identifier number and / or the fourth type identifier number, then the container health status assessment parameter is determined to be a third type container health status assessment parameter. For the case where the calculation process of the sum of the first and second identifier numbers only includes the second type identifier number:
[0093] That is, 4+0=4, 4+1=5.
[0094] The calculation process for the sum of the first and second identifier digits only includes the fourth type identifier digit:
[0095] 2 + 0 = 2.
[0096] The calculation process for the sum of the first and second identifier numbers includes cases involving the second and fourth type identifier numbers:
[0097] 2 + 4 = 6.
[0098] In other words, if the sum of the first and second identifier numbers is 2, 4, 5, or 6, then the third-type container health status assessment parameters are 2, 4, 5, or 6, indicating that the container is unhealthy. The higher the value of the third-type container health status assessment parameter, the more severe the unhealthy state of the container. Furthermore, the cause of the container's health condition can be determined based on the value of the third-type container health status assessment parameter. For example, a third-type container health status assessment parameter of 2 indicates that the container's safety indicators are normal, but its performance indicators are abnormal.
[0099] For example, if the health status assessment parameter for a third type of container is 4, it indicates that the container's safety indicators are abnormal, while its performance indicators are normal.
[0100] For example, if the health status assessment parameter for a third type of container is 5, it indicates that the container's safety indicators are abnormal and its performance indicators are in a warning state.
[0101] For example, if the health status assessment parameter for a third type of container is 6, it indicates that the container's safety indicators are abnormal and its performance indicators are in a warning state.
[0102] Furthermore, the container health status assessment method of this invention can be implemented modularly, including: a configuration module, a monitoring module, an analysis module, and a reporting module, wherein:
[0103] The configuration module is used to obtain the container identifier based on the deployment file after a new container is detected to start, query the container's valid identity in the configuration system, obtain the container's registration information in the system, and configure parameters such as preset configuration time periods.
[0104] The monitoring module is used to obtain relevant metrics from the cgroups subsystem in real time and pass the monitoring data to the analysis module.
[0105] The analysis module is used to assess the health status of containers based on different metrics.
[0106] The reporting module is used to report the health status of containers to the management center.
[0107] The container health status assessment method provided in this invention detects container safety indicators and container performance indicators according to a preset configured time period; generates corresponding first and second identifier numbers based on the first detection results of the container safety indicators and the second detection results of the container performance indicators; and determines container health status assessment parameters based on the first and second identifier numbers. This method can quantitatively obtain the container health status and helps to take countermeasures against the container health status in advance based on the container health reminder status and container health warning status.
[0108] It should be noted that the container health status assessment method provided in this embodiment of the invention can be used in the financial field, or in any technical field other than the financial field. This embodiment of the invention does not limit the application field of the container health status assessment method.
[0109] Figure 2 This is a schematic diagram of the structure of a container health status assessment device provided in an embodiment of the present invention, as shown below. Figure 2 As shown, the container health status assessment device provided in this embodiment of the invention includes a detection unit 201, a generation unit 202, and an assessment unit 203, wherein:
[0110] The detection unit 201 is used to detect container safety indicators and container performance indicators according to a preset configured time period; the generation unit 202 is used to generate corresponding first and second identification numbers based on the first detection result of the container safety indicators and the second detection result of the container performance indicators; the evaluation unit 203 is used to determine container health status evaluation parameters for evaluating the health status of the container based on the first and second identification numbers.
[0111] Specifically, the detection unit 201 in the device is used to detect container safety indicators and container performance indicators according to a preset configuration time period; the generation unit 202 is used to generate corresponding first and second identification numbers based on the first detection result of the container safety indicators and the second detection result of the container performance indicators; and the evaluation unit 203 is used to determine container health status evaluation parameters for evaluating the health status of the container based on the first and second identification numbers.
[0112] The container health status assessment device provided in this embodiment of the invention detects container safety indicators and container performance indicators according to a preset configured time period; it generates corresponding first and second identifier numbers based on the first detection results of the container safety indicators and the second detection results of the container performance indicators; and it determines container health status assessment parameters based on the first and second identifier numbers, which can quantitatively obtain the container health status and help to take countermeasures against the container health status in advance based on the container health reminder status and container health warning status.
[0113] The generation unit 202 is specifically used for:
[0114] If the first test results of all container safety indicators are normal, then the first identification number is determined to be a first type identification number; if the first test result of at least one container safety indicator is abnormal, then the first identification number is determined to be a second type identification number.
[0115] The embodiments of the present invention provide a container health status assessment device that can be used to execute the processing flow of the above method embodiments. Its functions will not be repeated here, but can be referred to the detailed description of the above method embodiments.
[0116] Figure 3 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as... Figure 3 As shown, the electronic device includes: a processor 301, a memory 302, and a bus 303;
[0117] The processor 301 and the memory 302 communicate with each other via the bus 303.
[0118] The processor 301 is used to call program instructions in the memory 302 to execute the methods provided in the above-described method embodiments, including, for example:
[0119] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0120] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0121] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0122] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can perform the methods provided in the above-described method embodiments, such as:
[0123] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0124] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0125] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0126] This embodiment provides a computer-readable storage medium storing a computer program that causes the computer to execute the methods provided in the above-described method embodiments, including, for example:
[0127] Detect container safety metrics and container performance metrics according to preset configuration time periods;
[0128] Based on the first test result of the container safety index and the second test result of the container performance index, generate their respective first and second identification numbers.
[0129] The container health status assessment parameters are determined based on the first identification number and the second identification number.
[0130] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0131] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0132] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0133] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0134] In the description of this specification, the references to terms such as "an embodiment," "a specific embodiment," "some embodiments," "for example," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0135] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Citation Information
Patent Citations
Server performance index evaluation method for container bearing service application
CN106557353A
Distributed network service risk monitoring and scoring
US10313211B1