Container Application Script Execution Method, Device, System, Electronic Device and Medium
By obtaining and using container private keys and springboard private keys, the security and process blocking problems during container application script execution are solved, and a more efficient and secure container application script execution method is achieved.
Patent Information
- Application Number
- CN202210385962.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-13
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-04-13
AI Technical Summary
When executing application scripts in containers, the prior art requires the use of passwords or tokens, resulting in poor container security and may lead to thread creation failures and container process blockage when the container memory resources are insufficient.
By obtaining the container private key, springboard identification and springboard private key from the key management system, connecting to the springboard private key using the springboard private key, and then connecting to the container through the container private key, executing the container application script command, and returning the result.
Improves the security of containers, avoids security issues caused by password or token leakage, and avoids process blockage when the container memory resources are insufficient.
Smart Images

Figure CN114780976B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to methods, apparatuses, systems, electronic devices, and media for executing container application scripts. Background Art
[0002] Container technology is a lightweight virtualization technology. Applications can be integrated into containers to run within the containers. Currently, when executing application scripts of applications deployed in containers, the commonly adopted method is to send an application script execution command (e.g., a Kubernetes command or kubectl exec) to the container, causing the container to execute the application script.
[0003] However, when using the above method to execute application scripts of applications deployed in containers, the following technical problems often exist: The method of sending an execution command to the container requires the use of a password or a token. When the password or token is leaked, the security of the container is poor. Also, when the memory resources of the container are insufficient, the method of sending an execution command to the container causes the thread creation to fail, and further causes the process of the container to block (the container hangs). Summary of the Invention
[0004] The content part of the present disclosure is used to briefly introduce concepts, which will be described in detail in the subsequent detailed implementation part. The content part of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution. Some embodiments of the present disclosure propose methods, apparatuses, systems, electronic devices, and computer-readable media for solving the technical problems mentioned in the above background art part.
[0005] In a first aspect, some embodiments of the present disclosure provide a method for executing a container application script, which is applied to a container management platform. The method includes: in response to receiving a container application script execution request, obtaining a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system, where the container application script execution request corresponding container application is deployed in the container corresponding to the container private key; connecting to the jump server corresponding to the jump server identifier through the jump server private key, where the jump server stores a jump server public key corresponding to the jump server private key; sending the container private key and the container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server sends the container application script execution command to the container after connecting to the container through the container private key, where the container stores a container public key corresponding to the container private key; in response to receiving the container application script execution result corresponding to the container application script execution command sent by the jump server, sending the container application script execution result to the request side corresponding to the container application script execution request.
[0006] Optionally, the sending the container application script execution result to the request side corresponding to the container application script execution request includes: sending key connection destruction information to the key management system, where the key connection destruction information represents destroying the key connection information corresponding to the container application script execution command in the key management system; sending the container application script execution result to the request side corresponding to the container application script execution request.
[0007] Optionally, after the sending the container application script execution result to the request side corresponding to the container application script execution request, the method further includes: sending key connection destruction information to the key management system, where the key connection destruction information represents destroying the key connection information corresponding to the container application script execution command in the key management system.
[0008] Optionally, the jump server identifier is randomly selected by the key management system from a set of jump server identifiers corresponding to the key management system in response to receiving a connection information acquisition request corresponding to the container application script execution request.
[0009] Optionally, the jump server private key is generated by the jump server through the following steps: in response to the current time being a preset periodic time, executing a jump server key generation script stored locally to obtain a jump server key, where the jump server key includes the jump server private key and the jump server public key; sending the jump server private key to the key management system.
[0010] Second aspect, some embodiments of the present disclosure provide a container application script execution device, which is applied to a container management platform. The device includes: an acquisition unit configured to, in response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system, where the container in which the container private key corresponds deploys the container application corresponding to the container application script execution request; a connection unit configured to connect to the jump server corresponding to the jump server identifier through the jump server private key, where the jump server stores a jump server public key corresponding to the jump server private key; a first sending unit configured to send the container private key and a container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server sends the container application script execution command to the container after connecting to the container through the container private key, where the container stores a container public key corresponding to the container private key; a second sending unit configured to, in response to receiving a container application script execution result corresponding to the container application script execution command sent by the jump server, send the container application script execution result to a request side corresponding to the container application script execution request.
[0011] Optionally, the second sending unit is further configured to: send key connection destruction information to the key management system, where the key connection destruction information represents destroying key connection information corresponding to the container application script execution command in the key management system; send the container application script execution result to a request side corresponding to the container application script execution request.
[0012] Optionally, after the second sending unit, the device further includes: a key connection destruction information sending unit configured to send key connection destruction information to the key management system, where the key connection destruction information represents destroying key connection information corresponding to the container application script execution command in the key management system.
[0013] Optionally, the jump server identifier is randomly selected by the key management system from a jump server identifier set corresponding to the key management system in response to receiving a connection information acquisition request corresponding to the container application script execution request.
[0014] Optionally, the jump server private key is generated by the jump server through the following steps: in response to the current time being a preset periodic time, execute a jump server key generation script stored locally to obtain a jump server key, where the jump server key includes the jump server private key and the jump server public key; send the jump server private key to the key management system.
[0015] In a third aspect, some embodiments of the present disclosure provide a container application script execution system, which includes: a container management platform configured to implement the method described in any implementation manner of the first aspect above; a jump server configured to: generate a jump server public key and a jump server private key; send the jump server private key to the key management system; receive the container private key and the container application script execution command sent by the container management platform; connect to the container through the container private key; send the container application script execution command to the container; send the container application script execution result sent by the received container to the container management platform; a key management system configured to: store the jump server private key sent by the jump server; determine the jump server identifier in response to receiving a key connection information acquisition request corresponding to a container application script execution request; generate a container public key and a container private key corresponding to the jump server identifier; connect to the container according to the private key of the container corresponding to the received container application script execution request; send the container public key and the jump server identifier to the container; send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform; a container configured to: generate a public key and a private key; send the private key to the key management system; store the container public key and the jump server identifier sent by the key management system; execute the container application script corresponding to the container application script execution command in response to receiving the container application script execution command sent by the jump server; send the obtained container application script execution result to the jump server.
[0016] Optionally, the container is further configured to: in response to the completion of storing the container public key and the jump server identifier, send a storage result indicating successful storage to the key management system.
[0017] Optionally, the key management system is further configured to: in response to receiving the storage result indicating successful storage sent by the container, send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform.
[0018] In a fourth aspect, some embodiments of the present disclosure provide an electronic device, which includes: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method described in any implementation manner of the first aspect above.
[0019] In a fifth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, where the program, when executed by a processor, implements the method described in any implementation manner of the first aspect above.
[0020] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the container application script execution method of some embodiments of the present disclosure, the security of the container is improved, and the process blockage of the container is avoided. Specifically, the reasons for the poor security of the container and the process blockage of the container are as follows: The method of sending an execution command to the container needs to use a password or a token. When the password or token is leaked, the security of the container is poor. And when the memory resources of the container are insufficient, the method of sending an execution command to the container causes the thread creation to fail, thereby causing the process blockage of the container (the container hangs). Based on this, in the container application script execution method of some embodiments of the present disclosure, first, in response to receiving a container application script execution request, obtain the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier from the key management system. Among them, the container corresponding to the above container private key deploys the container application corresponding to the above container application script execution request. Thus, when it is necessary to execute the container application script, the jump server identifier, the jump server private key for connecting to the jump server corresponding to the jump server identifier, and the container private key for the jump server corresponding to the jump server identifier to connect to the container corresponding to the container application script execution request can be obtained from the key management system. Then, connect to the jump server corresponding to the jump server identifier through the above jump server private key. Among them, the jump server public key corresponding to the above jump server private key is stored in the above jump server. Thus, the jump server private key can be used to connect to the jump server corresponding to the jump server identifier through the jump server public key corresponding to the jump server private key stored in the jump server corresponding to the jump server identifier. After that, send the above container private key and the container application script execution command corresponding to the above container application script execution request to the above jump server, so that the above jump server connects to the above container through the above container private key and then sends the above container application script execution command to the above container. Among them, the container public key corresponding to the above container private key is stored in the above container. Thus, the container private key sent to the jump server can be used by the jump server to connect to the container through the received container private key and the container public key corresponding to the container private key stored in the container, so that the container executes the container application script execution command to send the container application script execution result after executing the container application script to the jump server. Finally, in response to receiving the container application script execution result corresponding to the above container application script execution command sent by the above jump server, send the above container application script execution result to the request side corresponding to the above container application script execution request. Thus, after receiving the container application script execution result sent by the jump server, the received container application script execution result can be sent to the request side corresponding to the above container application script execution request to respond to the container application script execution request of the request side. Also, because the method of sending an execution command to the container is not used to execute the application script of the application deployed in the container, there is no need to use a password or a token, avoiding the leakage of the password or the token.Moreover, since the application script deployed in the container is not executed by sending an execution command to the container, even when the container's memory resources are insufficient, it is possible to avoid the process blockage (container hang) of the container. Thus, the security of the container is improved and the process blockage of the container is avoided. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the elements and elements are not necessarily drawn to scale.
[0022] Figure 1 is a schematic diagram of an application scenario of a method for executing a container application script according to some embodiments of the present disclosure;
[0023] Figure 2 is a flowchart of some embodiments of a method for executing a container application script according to the present disclosure;
[0024] Figure 3 is a schematic structural diagram of some embodiments of a container application script execution system according to the present disclosure;
[0025] Figure 4 is a timing diagram of some embodiments of a container application script execution system according to the present disclosure;
[0026] Figure 5 is a schematic structural diagram of some embodiments of a container application script execution device according to the present disclosure;
[0027] Figure 6 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] The embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for illustrative purposes and are not used to limit the protection scope of the present disclosure.
[0029] In addition, it should be noted that, for the sake of convenience of description, only the parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0030] It should be noted that the concepts such as "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or mutual dependence relationship of the functions performed by these devices, modules or units.
[0031] It should be noted that the modification of "one" and "multiple" mentioned in this disclosure is illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0032] The names of the messages or information exchanged between multiple devices in the embodiments of this disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0033] The following will detail this disclosure with reference to the accompanying drawings and in conjunction with embodiments.
[0034] Figure 1 is a schematic diagram of an application scenario of a container application script execution method according to some embodiments of this disclosure.
[0035] In Figure 1 the application scenario, first, the computing device 101 can, in response to receiving a container application script execution request 102, obtain a container private key 103, a jump server identifier 104, and a jump server private key 105 corresponding to the jump server identifier 104 from a key management system. Among them, the container corresponding to the container private key 103 deploys the container application corresponding to the container application script execution request 102. Then, the computing device 101 can connect to the jump server 106 corresponding to the jump server identifier 104 through the jump server private key 105. Among them, the jump server 106 stores a jump server public key corresponding to the jump server private key 105. After that, the computing device 101 can send the container private key 103 and a container application script execution command 107 corresponding to the container application script execution request 102 to the jump server 106, so that the jump server 106 connects to the container through the container private key 103 and then sends the container application script execution command 107 to the container. Among them, the container stores a container public key corresponding to the container private key 103. Finally, the computing device 101 can, in response to receiving a container application script execution result 108 corresponding to the container application script execution command 107 sent by the jump server 106, send the container application script execution result 108 to a request end 109 corresponding to the container application script execution request 102.
[0036] It should be noted that the above computing device 101 can be hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster composed of multiple servers or terminal devices, or as a single server or a single terminal device. When the computing device is embodied as software, it can be installed in the above-listed hardware devices. It can be implemented as, for example, multiple software or software modules for providing distributed services, or as a single software or software module. No specific limitation is made here.
[0037] It should be understood that Figure 1 the number of computing devices in
[0038] Continuing to refer to Figure 2 FIG. , a flowchart 200 of some embodiments of a method for executing a container application script according to the present disclosure is shown. The method for executing a container application script, which is applied to a container management platform, includes the following steps:
[0039] Step 201, in response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system.
[0040] In some embodiments, the execution entity of the method for executing a container application script (such as Figure 1 the computing device 101 shown) can, in response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the above jump server identifier from a key management system through a wired connection method or a wireless connection method. Among them, the container corresponding to the above container private key deploys the container application corresponding to the above container application script execution request. The above container application script execution request can be a request for causing the container in which the container application is deployed to execute the container application script. The above container application can be an application deployed in a container to run. The above container can be a container cluster in which the above container application is deployed. The above container cluster can be each node device in which one or more containers are deployed. For example, the above container can be each computing device in which Docker containers are deployed. The above container application script can be a script related to the above container application. For example, the above container application script can be a script for starting, stopping, or restarting the above container application. Another example is that the above container application script can be a script customized by a user for the above container application. The above container application script execution request can be sent by a computing device corresponding to the above browser page or the above application program interface after the user performs a container application script execution trigger operation through the browser page or the application program interface.
[0041] The above key management system can be used to manage the public and private keys for the jump server to connect to the container. The above container private key can be the private key used for the jump server corresponding to the jump server identifier to connect to the above container. The above container private key can be generated by the above key management system through an open-source toolkit in response to the connection information acquisition request of the above execution subject. The above connection information acquisition request can be a request sent by the above execution subject to the above key management system for acquiring connection information. The above connection information can be the information required to establish a connection, and can include the above container private key, the above jump server identifier, and the above jump server private key. The above toolkit can be a Java jar package, for example, com.jcraft.jsch.JSch or java.security.KeyPair. The above jump server identifier can uniquely represent the jump server. For example, the above jump server identifier can be the IP address of the jump server. The above jump server identifier can be selected by the above key management system from the corresponding set of jump server identifiers in a polling manner in response to receiving the connection information acquisition request corresponding to the above container application script execution request. The above set of jump server identifiers can be a set of identifiers of the jump servers managed by the above key management system. The above jump server private key can be generated by the above jump server through the following steps:
[0042] In the first step, in response to the current time being a preset periodic time, call the key generation interface to obtain a key as the jump server key. Among them, the above jump server key includes the above jump server private key and the jump server public key corresponding to the above jump server private key. The above key generation interface can be the interface of the above key management system for generating keys. The above periodic time can be at least one time set in advance for generating the jump server key. For example, the above periodic time can be 8 o'clock, 12 o'clock, and 18 o'clock every day.
[0043] In the second step, send the above jump server private key to the above key management system.
[0044] Thus, when it is necessary to execute the container application script, the jump server identifier, the jump server private key for connecting to the jump server corresponding to the jump server identifier, and the container private key for the jump server corresponding to the jump server identifier to connect to the container corresponding to the container application script execution request can be obtained from the key management system.
[0045] Optionally, the above jump server identifier can be randomly selected by the above key management system from the set of jump server identifiers corresponding to the above key management system in response to receiving the connection information acquisition request corresponding to the above container application script execution request. Thus, after the key management system receives the connection information acquisition request, a jump server identifier can be randomly selected and returned to the above execution subject.
[0046] Optionally, the above jump server private key is generated by the above jump server through the following steps:
[0047] First, in response to the current time being a preset periodic time, execute the jump server key generation script stored locally to obtain the jump server key. Among them, the jump server key includes the jump server private key and the jump server public key. Among them, the jump server key generation script can be a script pre-stored in the jump server for generating the jump server key.
[0048] Second, send the jump server private key to the key management system.
[0049] It should be noted that the above wireless connection methods can include, but are not limited to, 3G / 4G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future-developed wireless connection methods.
[0050] Step 202: Connect to the jump server corresponding to the jump server identifier through the jump server private key.
[0051] In some embodiments, the above execution entity can connect to the jump server corresponding to the jump server identifier through the jump server private key. Among them, the jump server stores the jump server public key corresponding to the jump server private key. In practice, the above execution entity can send a connection request including the jump server private key to the jump server, so that after the jump server determines that the jump server private key and the jump server public key match, it responds to the connection request of the execution entity. Thus, it is possible to connect to the jump server corresponding to the jump server identifier through the jump server public key corresponding to the jump server private key stored in the jump server corresponding to the jump server identifier.
[0052] Step 203: Send the container private key and the container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server connects to the container through the container private key and then sends the container application script execution command to the container.
[0053] In some embodiments, the above-mentioned execution entity may send the above-mentioned container private key and the container application script execution command corresponding to the above-mentioned container application script execution request to the above-mentioned jump server, so that the jump server connects to the above-mentioned container through the above-mentioned container private key and then sends the above-mentioned container application script execution command to the above-mentioned container. Among them, the above-mentioned container stores the container public key corresponding to the above-mentioned container private key. The above-mentioned container application script execution command may be a command for causing the above-mentioned container to execute the container application script corresponding to the above-mentioned container application script execution request. The above-mentioned jump server may send a connection request including the above-mentioned container private key to the above-mentioned container, so that after the above-mentioned container determines that the above-mentioned container private key and the above-mentioned container public key match, it responds to the connection request sent by the above-mentioned jump server. After receiving the above-mentioned container application script execution command, the above-mentioned container may execute the above-mentioned container application script, obtain the container application script execution result, and send the container application script execution result to the above-mentioned jump server, so that the jump server sends the above-mentioned container application script execution result to the above-mentioned execution entity. The above-mentioned container application script execution result may be a result indicating whether the execution of the above-mentioned container application script execution command is successful or failed. Thus, the container private key sent to the jump server can be used by the jump server to connect to the container through the received container private key and the container public key stored in the container, so that the container executes the container application script execution command to send the container application script execution result after executing the container application script to the jump server.
[0054] Step 204, in response to receiving the container application script execution result corresponding to the container application script execution command sent by the jump server, send the container application script execution result to the request end corresponding to the container application script execution request.
[0055] In some embodiments, the above-mentioned execution entity may, in response to receiving the container application script execution result corresponding to the above-mentioned container application script execution command sent by the above-mentioned jump server, send the above-mentioned container application script execution result to the request end corresponding to the above-mentioned container application script execution request. Among them, the above-mentioned request end may be a computing device that sends the above-mentioned container application script execution request. In practice, the above-mentioned execution entity may send the above-mentioned container application script execution result to the above-mentioned request end through a wired connection method or a wireless connection method, so that the above-mentioned request end displays the above-mentioned container application script execution result. Thus, after receiving the container application script execution result sent by the jump server, the received container application script execution result can be sent to the request end corresponding to the above-mentioned container application script execution request to respond to the container application script execution request of the request end.
[0056] In some alternative implementation manners of some embodiments, first, the above-mentioned execution entity may send key connection destruction information to the above-mentioned key management system. The key connection destruction information may represent the destruction of the key connection information corresponding to the container application script execution command in the above-mentioned key management system. The key connection information may be key-related information required for establishing a connection, and may include, but is not limited to: the bastion host private key, the container public key, and the container private key. After receiving the key connection destruction information, the above-mentioned key management system may delete the key connection information. Then, the execution result of the container application script may be sent to the request side corresponding to the container application script execution request. Thus, before returning the execution result of the container application script, the key management system can be made to destroy the key connection information used when executing the container application script this time, so that new key connection information is used when executing the container application script next time.
[0057] Optionally, the above-mentioned execution entity may also send key connection destruction information to the above-mentioned key management system. The key connection destruction information represents the destruction of the key connection information corresponding to the container application script execution command in the above-mentioned key management system. Thus, after returning the execution result of the container application script, the key management system can be made to destroy the key connection information used when executing the container application script this time, so that new key connection information is used when executing the container application script next time. It should be noted that the above-mentioned key management system may also send container key connection destruction information to the above-mentioned container in response to deleting the key connection information. The container key connection destruction information may represent the destruction of the container key connection information corresponding to the container application script execution command in the above-mentioned container. The container key connection information may include, but is not limited to: the container public key.
[0058] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the container application script execution method of some embodiments of the present disclosure, the security of the container is improved, and the process blockage of the container is avoided. Specifically, the reasons for the poor security of the container and the process blockage of the container are as follows: The method of sending an execution command to the container needs to use a password or a token. When the password or token is leaked, the security of the container is poor, and when the method of sending an execution command to the container has insufficient memory resources in the container, it causes the thread creation to fail, thereby causing the process blockage of the container (the container hangs). Based on this, in the container application script execution method of some embodiments of the present disclosure, first, in response to receiving a container application script execution request, obtain the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier from the key management system. Among them, the container corresponding to the above container private key deploys the container application corresponding to the above container application script execution request. Thus, when it is necessary to execute the container application script, the jump server identifier, the jump server private key for connecting to the jump server corresponding to the jump server identifier, and the container private key for the jump server corresponding to the jump server identifier to connect to the container corresponding to the container application script execution request can be obtained from the key management system. Then, connect to the jump server corresponding to the jump server identifier through the above jump server private key. Among them, the jump server stores the jump server public key corresponding to the above jump server private key. Thus, it is possible to connect to the jump server corresponding to the jump server identifier through the jump server public key corresponding to the jump server private key stored in the jump server corresponding to the jump server private key. After that, send the above container private key and the container application script execution command corresponding to the above container application script execution request to the above jump server, so that the above jump server connects to the above container through the above container private key and then sends the above container application script execution command to the above container. Among them, the container stores the container public key corresponding to the above container private key. Thus, the container private key sent to the jump server can be used by the jump server to connect to the container through the received container private key and the container public key stored in the container corresponding to the container private key, so that the container executes the container application script execution command to send the container application script execution result after executing the container application script to the jump server. Finally, in response to receiving the container application script execution result corresponding to the above container application script execution command sent by the above jump server, send the above container application script execution result to the request side corresponding to the above container application script execution request. Thus, after receiving the container application script execution result sent by the jump server, the received container application script execution result can be sent to the request side corresponding to the above container application script execution request to respond to the container application script execution request of the request side. Also, because the method of sending an execution command to the container is not used to execute the application script of the application deployed in the container, there is no need to use a password or a token, avoiding the leakage of the password or the token.Moreover, since the application script of the application deployed in the container is not executed by sending an execution command to the container, even when the container memory resources are insufficient, the process blocking (container hanging) of the container can be avoided. Thus, the security of the container is improved and the process blocking of the container is avoided.
[0059] Further referring to Figure 3 , which shows a schematic structural diagram 300 of some embodiments of a container application script execution system. The container application script execution system 300 includes:
[0060] A container management platform 301, configured to implement Figure 2 The methods described in steps 201-204 in the corresponding embodiments.
[0061] A jump server 302, configured to: generate a jump server public key and a jump server private key; send the jump server private key to a key management system 303; receive the container private key and the container application script execution command sent by the container management platform 301; connect to the container 304 through the container private key; send the container application script execution command to the container 304; send the container application script execution result sent by the received container 304 to the container management platform 301.
[0062] In some embodiments, the jump server 302 may generate a jump server public key and a jump server private key in response to the current time being a preset periodic time. Thus, the jump server public key and the jump server private key for connecting to the container management platform can be updated regularly.
[0063] A key management system 303, configured to: store the jump server private key sent by the jump server 302; determine the jump server identifier in response to receiving a key connection information acquisition request corresponding to a container application script execution request; generate a container public key and a container private key corresponding to the jump server identifier; connect to the container 304 according to the private key of the container received corresponding to the container application script execution request; send the container public key and the jump server identifier to the container 304; send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform 301.
[0064] In some optional implementation manners of some embodiments, the key management system 303 may send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform 301 through the following steps: in response to receiving the storage result indicating successful storage sent by the container 304, send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform 301.
[0065] The container 304 is configured to: generate a public key and a private key; send the private key to the key management system 303; store the container public key and the jump server identifier sent by the key management system 303; in response to receiving the container application script execution command sent by the jump server 302, execute the container application script corresponding to the container application script execution command; and send the obtained container application script execution result to the jump server 302.
[0066] In some embodiments, the container 304 may generate a public key and a private key for the connection between the key management system 303 and the container 304 in response to the current time being a preset periodic time. The container 304 may call a key generation interface or execute a locally stored key generation script to obtain the public key and the private key. The key generation script may be a script for generating the public key and the private key. The public key and the private key are used for the key management system 303 to connect to the container 304. The container application script may be a script of a container application pre-stored in the container 304, or a container application script generated when executing the container application script execution command. The container 304 may add the jump server identifier to the SSH (Secure Shell) white list to store the jump server identifier.
[0067] Optionally, the container 304 may further send a storage result indicating successful storage to the key management system in response to the completion of the storage of the container public key and the jump server identifier. The storage result indicating successful storage may be represented by any character or string. For example, the storage result indicating successful storage may be "success".
[0068] It should be noted that the above container may be a distributed container cluster. There is no limit on the number of containers included in the container cluster.
[0069] From Figure 3 it can be seen that Figure 3 In some corresponding embodiments, the container application script execution system 300 reflects the composition of the container application script execution system. Thus, through the container application script execution system in some embodiments composed of a container management platform, a jump server, a key management system, and a container, the security of the container is improved, and the process blockage of the container is avoided.
[0070] Further referring to Figure 4 , which shows a timing diagram of some embodiments of the container application script execution system. The process 400 of the container application script execution system corresponds to the system embodiments shown in Figure 3 and includes the following steps:
[0071] Step 401, the jump server generates a jump server public key and a jump server private key.
[0072] Step 402: The jump server sends the private key of the jump server to the key management system.
[0073] Step 403: The container generates a public key and a private key.
[0074] Step 404: The container sends the private key to the key management system.
[0075] Step 405: The container management platform receives the container application script execution request sent by the request side.
[0076] Step 406: The container management platform requests to obtain the container private key, the jump server identifier, and the private key of the jump server corresponding to the jump server identifier from the key management system.
[0077] Step 407: The key management system determines the jump server identifier, and generates the container public key and the container private key corresponding to the jump server identifier.
[0078] Step 408: The key management system connects to the container according to the received private key, and sends the container public key and the jump server identifier to the container.
[0079] Step 409: The container stores the received container public key and the jump server identifier.
[0080] Step 410: The key management system sends the container private key, the jump server identifier, and the private key of the jump server corresponding to the jump server identifier to the container management platform.
[0081] Step 411: The container management platform connects to the jump server through the private key of the jump server, and sends the container private key and the container application script execution command corresponding to the container application script execution request to the jump server.
[0082] Step 412: The jump server connects to the container through the container private key, and sends the container application script execution command to the container.
[0083] Step 413: The container executes the container application script corresponding to the container application script execution command.
[0084] Step 414: The container sends the obtained container application script execution result to the jump server.
[0085] Step 415: The jump server sends the received container application script execution result to the container management platform.
[0086] Step 416: The container management platform sends the container application script execution result to the request side.
[0087] In some embodiments, for the specific implementation and the technical effects brought by steps 401 - 416, reference can be made to Figure 2 steps 201 - 204 in the corresponding embodiments, andFigure 3 For the corresponding embodiments, they will not be elaborated here.
[0088] From Figure 4 it can be seen that Figure 4 In the process 400 of the container application script execution system in some corresponding embodiments, the interaction steps among the container management platform, the jump server, the key management system, and the containers are reflected. Thus, the solutions described in these embodiments improve the security of the containers and avoid the process blockage of the containers.
[0089] Further referring to Figure 5 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a container application script execution device. These device embodiments correspond to Figure 2 the method embodiments shown, and the device can be specifically applied to various electronic devices.
[0090] As Figure 5 shown, the container application script execution device 500 in some embodiments includes: an acquisition unit 501, a connection unit 502, a first sending unit 503, and a second sending unit 504. Among them, the acquisition unit 501 is configured to, in response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from the key management system. Among them, the container corresponding to the container private key deploys the container application corresponding to the container application script execution request; the connection unit 502 is configured to connect to the jump server corresponding to the jump server identifier through the jump server private key, where the jump server stores a jump server public key corresponding to the jump server private key; the first sending unit 503 is configured to send the container private key and the container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server sends the container application script execution command to the container after connecting to the container through the container private key, where the container stores a container public key corresponding to the container private key; the second sending unit 504 is configured to, in response to receiving the container application script execution result corresponding to the container application script execution command sent by the jump server, send the container application script execution result to the request side corresponding to the container application script execution request.
[0091] Optionally, the second sending unit 504 of the container application script execution device 500 can be further configured to: send key connection destruction information to the key management system, where the key connection destruction information represents the destruction of the key connection information corresponding to the container application script execution command in the key management system; send the container application script execution result to the request side corresponding to the container application script execution request.
[0092] Optionally, after the second sending unit 504, the container application script execution device 500 may further include: a key connection destruction information sending unit (not shown in the figure), configured to send key connection destruction information to the above-mentioned key management system, where the key connection destruction information represents the key connection information corresponding to the container application script execution command in the above-mentioned key management system to be destroyed.
[0093] Optionally, the above-mentioned jump server identifier is randomly selected by the above-mentioned key management system from the set of jump server identifiers corresponding to the above-mentioned key management system in response to a connection information acquisition request corresponding to the container application script execution request.
[0094] Optionally, the above-mentioned jump server private key is generated by the above-mentioned jump server through the following steps: in response to the current time being a preset periodic time, execute a jump server key generation script stored locally to obtain a jump server key, where the jump server key includes the above-mentioned jump server private key and the above-mentioned jump server public key; send the above-mentioned jump server private key to the above-mentioned key management system.
[0095] It can be understood that the various units described in the device 500 correspond to the respective steps in the method described with reference to Figure 2 Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 500 and the units included therein, and will not be elaborated herein.
[0096] Next, with reference to Figure 6 , which shows a schematic structural diagram of an electronic device (such as Figure 1 the computing device 101 in Figure 6 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0097] As Figure 6 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0098] Typically, the following devices can be connected to the I / O interface 605: input devices 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and a communication device 609. The communication device 609 can allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices can be alternatively implemented or had. Figure 6 Each block shown in
[0099] can represent one device or, as required, multiple devices.
[0100] It should be noted that the computer-readable media described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0101] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0102] The above computer-readable medium may be included in the above electronic device; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: in response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system, wherein the container corresponding to the container private key deploys the container application corresponding to the container application script execution request; connect to the jump server corresponding to the jump server identifier through the jump server private key, wherein the jump server stores a jump server public key corresponding to the jump server private key; send the container private key and a container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server sends the container application script execution command to the container after connecting to the container through the container private key, wherein the container stores a container public key corresponding to the container private key; and in response to receiving a container application script execution result corresponding to the container application script execution command sent by the jump server, send the container application script execution result to a request end corresponding to the container application script execution request.
[0103] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++; and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0104] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0105] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes an acquisition unit, a connection unit, a first transmission unit, and a second transmission unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit can also be described as "the unit that, in response to receiving a container application script execution request, obtains a container private key, a jump server identifier, and a jump server private key corresponding to the above jump server identifier from a key management system".
[0106] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and so on.
[0107] The above description is only some preferred embodiments of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A method for executing a container application script, which is applied to a container management platform, including: In response to receiving a container application script execution request, obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system, where the container in which the container private key corresponds deploys the container application corresponding to the container application script execution request; Connect to the jump server corresponding to the jump server identifier through the jump server private key, where the jump server stores a jump server public key corresponding to the jump server private key; Send the container private key and the container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server connects to the container through the container private key and then sends the container application script execution command to the container, where the container stores a container public key corresponding to the container private key; In response to receiving the container application script execution result corresponding to the container application script execution command sent by the jump server, send the container application script execution result to the request end corresponding to the container application script execution request.
2. The method according to claim 1, wherein, the sending the container application script execution result to the request end corresponding to the container application script execution request includes: Sending key connection destruction information to the key management system, where the key connection destruction information represents destroying the key connection information corresponding to the container application script execution command in the key management system; Sending the container application script execution result to the request end corresponding to the container application script execution request.
3. The method according to claim 1, wherein, after the sending the container application script execution result to the request end corresponding to the container application script execution request, the method further includes: Sending key connection destruction information to the key management system, where the key connection destruction information represents destroying the key connection information corresponding to the container application script execution command in the key management system.
4. The method according to claim 1, wherein, the jump server identifier is randomly selected by the key management system from a set of jump server identifiers corresponding to the key management system in response to receiving a connection information acquisition request corresponding to the container application script execution request.
5. The method according to any one of claims 1-4, wherein, the jump server private key is generated by the jump server through the following steps: In response to the current time being a preset cycle time, execute a jump server key generation script stored locally to obtain a jump server key, where the jump server key includes the jump server private key and the jump server public key; Send the jump server private key to the key management system.
6. A device for executing a container application script, which is applied to a container management platform, including: An acquisition unit, configured to obtain a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system in response to receiving a container application script execution request, wherein the container private key corresponds to a container in which the container application script execution request corresponding container application is deployed; A connection unit, configured to connect to the jump server corresponding to the jump server identifier through the jump server private key, wherein the jump server stores a jump server public key corresponding to the jump server private key; A first sending unit, configured to send the container private key and a container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server connects to the container through the container private key and then sends the container application script execution command to the container, wherein the container stores a container public key corresponding to the container private key; A second sending unit, configured to send the container application script execution result to a request end corresponding to the container application script execution request in response to receiving the container application script execution result corresponding to the container application script execution command sent by the jump server.
7. A container application script execution system, comprising: A container management platform, configured to implement the method according to any one of claims 1-5; A jump server, configured to: generate a jump server public key and a jump server private key; send the jump server private key to the key management system; receive the container private key and the container application script execution command sent by the container management platform; connect to the container through the container private key; send the container application script execution command to the container; send the container application script execution result sent by the received container to the container management platform; A key management system, configured to: store the jump server private key sent by the jump server; determine a jump server identifier in response to receiving a key connection information acquisition request corresponding to a container application script execution request; generate a container public key and a container private key corresponding to the jump server identifier; connect to the container according to the private key of the container corresponding to the received container application script execution request; send the container public key and the jump server identifier to the container; send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform; A container, configured to: generate a public key and a private key; send the private key to the key management system; store the container public key and the jump server identifier sent by the key management system; execute a container application script corresponding to the container application script execution command in response to receiving the container application script execution command sent by the jump server; send the obtained container application script execution result to the jump server.
8. The system according to claim 7, wherein, the container is further configured to: send a storage result indicating successful storage to the key management system in response to completion of storage of the container public key and the jump server identifier.
9. The system according to claim 8, wherein, the key management system is further configured to: In response to receiving the storage result indicating successful storage sent by the container, send the container private key, the jump server identifier, and the jump server private key corresponding to the jump server identifier to the container management platform.
10. An electronic device, comprising: one or more processors; a storage device having stored thereon one or more programs, when the one or more programs are executed by the one or more processors, causing the one or more processors to implement the method according to any one of claims 1-5.
11. A computer-readable medium having stored thereon a computer program, wherein, when the program is executed by a processor, the method according to any one of claims 1-5 is implemented.
Citation Information
Patent Citations
Transaction signature processing method based on DAPP (Decentralized Application) container, system and electronic equipment
CN108900304A
Container management method and device and readable storage medium
CN111176794A