Method, device, equipment and system for downloading secure container image files
By creating an independent database and a specified directory in the virtual machine, the data security problem caused by the non-isolation of image files between secure containers is solved, high isolation and sharing of mirror layer data is achieved, and the container startup speed is improved.
Patent Information
- Application Number
- CN202210524702.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-05-13
AI Technical Summary
In multi-tenant scenarios, the non-isolation of mirror files between secure containers results in data security that cannot be guaranteed.
By creating an independent database in the virtual machine, storing the mapping relationship between the mirror layer identity and data, the mirror layer data of the same user is isolated, and the mirror layer data of the same user is stored in the specified directory, allowing the mirror layer data sharing between different virtual machines.
High isolation between different users is achieved, data leakage is avoided, and duplicate downloads are reduced through the sharing of mirror layer data, and the container startup speed is improved.
Smart Images

Figure CN114995948B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and in particular, to methods, devices, equipment, and systems for downloading secure container image files. Background Art
[0002] Nowadays, the container operation service combined with Serverless technology allows users to run their own containers by providing image files without maintaining servers. In multi-tenant scenarios, containers of different users deployed on the same server need to be highly isolated to ensure user data security. Secure containers that achieve virtual machine isolation level are commonly used container services in multi-tenant scenarios. Secure containers are created on micro virtual machines created by KVM virtualization technology, so that secure containers have high isolation at the virtual machine level, but data security cannot be guaranteed due to the non-isolation of image files between secure containers. Summary of the invention
[0003] To overcome the problems existing in the related art, this specification provides a method, device, equipment and system for downloading a secure container image file.
[0004] According to a first aspect of an embodiment of this specification, a method for downloading a secure container image file is provided, which is applied to a virtual machine, in which at least one secure container is running, and the image file includes at least one layer of image layer data, the method comprising:
[0005] Get the target image layer ID;
[0006] Querying whether there is target image layer data corresponding to the target image layer identifier in a specified directory, wherein the specified directory is used to store image layer data downloaded by each virtual machine accessible to the same user;
[0007] When the target image layer data is not found, downloading the target image layer data;
[0008] Storing the target image layer data in the specified directory;
[0009] The mapping relationship between the target image layer identifier and the storage path of the target image layer data is written into a target image database, where the target image database is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
[0010] According to a second aspect of an embodiment of this specification, there is provided a device for downloading a secure container image file, which is applied to a virtual machine, in which at least one secure container is running, and the image file includes at least one layer of image layer data, and the device includes:
[0011] The acquisition module is used to obtain the target image layer identifier;
[0012] A query module, used to query whether there is target image layer data corresponding to the target image layer identifier in a specified directory, wherein the specified directory is used to store image layer data downloaded by each virtual machine accessible to the same user;
[0013] A download module, used for downloading the target image layer data when the target image layer data is not found;
[0014] A first storage module, used to store the target image layer data in the specified directory;
[0015] The second storage module is used to write the mapping relationship between the target image layer identifier and the storage path of the target image layer data into a target image database, and the target image database is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
[0016] According to a third aspect of the embodiments of this specification, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.
[0017] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and the computer program is used to instruct related hardware to complete the method described in the first aspect above.
[0018] According to a fifth aspect of an embodiment of this specification, a distributed system is provided, the distributed system comprising a plurality of computer devices, the computer devices comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the method described in the first aspect above is implemented when the processor executes the program.
[0019] The technical solutions provided by the embodiments of this specification may have the following beneficial effects:
[0020] In the embodiments of this specification, the image data required to run the secure container is downloaded and managed by the virtual machine running the secure container. The virtual machine has an independent database for storing the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data, which realizes the isolation of image data between secure containers, thereby ensuring a high degree of isolation between secure containers of different users and avoiding data leakage. In addition, the image layer data of all secure containers accessible to a user is stored in the designated directory, so that the image layer data can be shared between different secure containers of the same user, thereby avoiding repeated downloading of image layer data, and thus increasing the speed of container startup.
[0021] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.
[0023] Figure 1 It is a schematic diagram of a safety container shown in this specification according to an exemplary embodiment.
[0024] Figure 2 The present specification is a flowchart of a method for downloading a secure container image according to an exemplary embodiment.
[0025] Figure 3A This is a schematic diagram of the process of a user creating a container provided in this manual.
[0026] Figure 3B The diagram is a schematic diagram of a process of a user creating a container according to an exemplary embodiment of the present specification.
[0027] Figure 4 It is a flowchart of a method for downloading a secure container image according to another exemplary embodiment of the present specification.
[0028] Figure 5 It is a hardware structure diagram of the computer device where the secure container image downloading device of the embodiment of this specification is located.
[0029] Figure 6 It is a block diagram of a device for downloading a secure container image according to an exemplary embodiment of the present specification.
[0030] Figure 7 It is a schematic diagram of a distributed system shown in this specification according to an exemplary embodiment. DETAILED DESCRIPTION
[0031] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this specification. Instead, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.
[0032] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "the" and "the" used in this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0033] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0034] Nowadays, container operation services combined with Serverless technology allow users to run their own containers by providing image files without maintaining servers. In multi-tenant scenarios, containers of different users deployed on the same server need to be highly isolated to ensure user data security. Secure containers that achieve virtual machine isolation levels are commonly used container services in multi-user scenarios.
[0035] Secure containers are different from traditional containers. Traditional containers limit and isolate resources, files, system calls, etc. in containers based on namespaces and cgroups provided by the kernel. Different containers running on the same physical machine share the kernel of the physical machine's operating system. Once one of the containers is attacked, the physical machine's operating system may be controlled, thereby affecting other containers.
[0036] Combining virtual machine technology can solve the security issues caused by the shared kernel mechanism of traditional containers. Through the simulation of the virtual machine hypervisor, each virtual machine running on the same physical machine has a complete computer system, each with an independent operating system and kernel. It is difficult for programs on virtual machines to break through the resource restrictions imposed by the virtualization layer, and due to the isolation of the kernel, the visibility of resources is also highly isolated. Even malicious users find it difficult to break through the restrictions of this layer of virtualization to attack the physical machine or other virtual machines on the same physical machine. Therefore, creating a container on a virtual machine can separate the operation of the container from the physical operating system on the one hand, and on the other hand, the container has its own independent kernel, which improves the isolation between containers while ensuring the security of the physical machine. However, the creation of a virtual machine consumes more computer resources, resulting in a slow startup speed, which hinders the application of virtual machines as container operating environments.
[0037] In order to balance the security advantages of virtual machines and the speed advantages of containers, secure containers came into being. KataContainer is a common secure container that uses a more lightweight virtual machine technology. It does not need to simulate a complete computer system for the virtual machine. It only needs to provide kernel space in the virtual machine for the container to run, thereby ensuring high isolation between containers while reducing performance loss and increasing the startup speed of the container.
[0038] However, even with secure containers, the security of data between different containers cannot be guaranteed. All containers deployed on the same physical machine are created and managed by the container runtime component running on the physical machine. The container runtime component maintains a public database for storing image data, and the image data stored in the public database is shared with each container. For example, user A can obtain user B's image data by accessing the public database, which will lead to the leakage of user B's data.
[0039] In response to the data security issues between different users caused by the non-isolation of image data, this specification proposes a method for downloading a secure container image file, and transferring the image service module in the container runtime component used to implement operations such as acquisition, management, and sharing of image files to a virtual machine running at least one secure container. The image file consists of at least one layer of image layer data. In other words, each virtual machine has its own independent database to store the mapping relationship between the identification of the image layer data and the corresponding image layer data storage path, that is, the mapping relationship is not shared between virtual machines, thereby achieving isolation of the image layer data stored in the virtual machine, and then achieving isolation of the image layer data between different users. In addition, the image layer data downloaded by each virtual machine is stored in a designated directory corresponding to the user to which the virtual machine belongs, so that the image layer data in the designated directory can be shared between virtual machines of the same user to create a secure container, thereby achieving sharing of image layer data between different containers of the same user.
[0040] Next, the embodiments of this specification are described in detail.
[0041] like Figure 1 As shown, Figure 1 This is a schematic diagram of a secure container in a multi-user scenario according to an exemplary embodiment of the present specification, in which a virtual machine 120 of user X and a virtual machine 130 of user Y are deployed on the same physical machine 110. The virtual machine 120 of user X and the virtual machine 130 of user Y each have their own kernel 140, and a container 150 belonging to user X and a container 160 belonging to user Y are respectively running therein.
[0042] like Figure 2 As shown, Figure 2 This is a flowchart of a method for downloading a secure container image file according to an exemplary embodiment of the present specification, which is applied to a virtual machine, each of which runs at least one secure container, and the image file includes at least one layer of image layer data, including the following steps:
[0043] Step 201, obtaining the target image layer identifier;
[0044] First of all, it should be noted that a complete image file is generally composed of a manifest file, a config file, and a layer file. The layer file has a layered feature, which contains the files and directories in the image, as well as their attributes and specific data. Each layer file records the changes made on the basis of the previous layer file, and mainly includes three aspects: the type of change, whether it is addition, modification or deletion; the file type, on which file type each change occurs; the file attributes, such as the modification time of the file, user ID, etc. For example, the second layer file adds a file based on the first layer file, then the content contained in the second layer file is the data of the added file and its attributes, and the bottom layer file is the base image. The format of each layer file can be tar or tar.gzip. It is worth noting that each layer file is independent of each other, and each layer file can be shared separately. For example, assuming that the image file a required by user G contains three layers: layer1, layer2 and layer3, and the image file b required by user H contains three layers: layer1, layer4 and layer5, then users G and H can share the data of layer1.
[0045] The config file contains a description of each layer file, such as the image layer identifier of each layer and the order of the layer files. The manifest file contains a description of the config file, such as the identifier of the config file, the file type, the file size, etc.
[0046] The complete image file image can be obtained from an official public image repository, such as DockerHub, or from a private image repository built by the user. When downloading a complete image file image, first download the manifest file and obtain the identifier of the config file from it, then download the corresponding config file to obtain the image layer identifier of each layer file, and download the compressed package of the corresponding layer file according to the image layer identifier. After each layer file contained in the image file is downloaded, the complete image file image is obtained. In other words, the download of layer files is carried out in layers. The method for downloading secure container images proposed in this specification can be applied to obtaining each layer file.
[0047] Step 203, querying whether there is target image layer data corresponding to the target image layer identifier in the designated directory, where the designated directory is used to store image layer data downloaded by each virtual machine accessible to the same user;
[0048] After each layer file (i.e., image layer data) is downloaded successfully, it will be stored in the specified directory. When storing, the image layer identifier corresponding to the layer file is used as its file name to query the corresponding target image layer data according to the target image layer identifier. The specified directory is a shared directory created for each user. When the same user creates different containers, all virtual machines belonging to the same user can access the specified directory to query or obtain the image layer data required to create the container. The specified directory is created based on the shared file system on the physical machine. In one embodiment of the present specification, the specified directory is created based on the virtiofs file system. The virtiofs file system is a file system that uses virtio and fuse to share folders between physical machines and virtual machines. In addition, it can also be created based on other shared file systems, and this specification does not limit this.
[0049] When two different containers of the same user use the same image layer data, by querying whether the image layer data exists in the specified directory, it can be determined whether the image layer data has been downloaded. If the image layer data is found, there is no need to download it again, and continue to obtain the next image layer identifier. For example, assuming that the target image layer identifier obtained by user G when creating a container is layer1, and layer1 is found in the specified directory corresponding to user G, it means that the image layer data corresponding to layer1 has been downloaded, and user G can directly obtain the image layer data corresponding to layer1 from the specified directory.
[0050] Step 205: when the target image layer data is not found, download the target image layer data;
[0051] Step 207, storing the target image layer data in a specified directory;
[0052] Step 209: write the mapping relationship between the target image layer identifier and the storage path of the target image layer data into the target image database, which is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
[0053] If the target image layer identifier is not found in the specified directory, it means that the target image layer data corresponding to the target image layer identifier has not been downloaded, and the target image layer data is then downloaded and stored in the specified directory. The image layer data stored in the specified directory for sharing can be a compressed package or decompressed data. In another embodiment of the present specification, before storing the target image layer data in the specified directory, it also includes: decompressing the target image layer data; separating the decompressed target image layer data into metadata and image data, and the metadata is used to characterize the storage structure of the image data. Decompressing the image layer data and then sharing it allows users to directly use the image layer data when creating other containers without decompressing it again, thereby saving decompression time and speeding up the startup of the container. In addition, separating the target image layer data into metadata and image data allows the management and access of the image layer data to be concentrated on only two files, thereby further improving the startup speed of the container. Considering that the data in rafs format has the characteristics of metadata and data separation, in another embodiment of the present specification, the step of separating the decompressed target image layer data into metadata and image data includes: converting the decompressed target image layer data into rafs format. The process of converting the image layer data into the rafs format can be implemented by the nydus accelerator. Other methods for separating the metadata of the image layer data from the image data are also applicable, and this manual does not limit this.
[0054] In addition, each virtual machine has its own independent image database. When running the container, the mapping relationship between the target image layer identifier and the target image layer data storage path in the target image database is queried to obtain the target image layer data from the specified directory. Therefore, the above mapping relationship also needs to be stored in the target image database.
[0055] In another embodiment of the present specification, before querying whether there is target image layer data corresponding to the target image layer identifier in the specified directory, query whether there is the target image layer identifier in the target image database. When sharing image layer data between different secure containers of the same user, the following situation exists: Assuming that virtual machine A downloads an image layer data a when creating a secure container, virtual machine B also needs to download image layer data a when creating a container. When virtual machine B uses image layer data a for the first time, the mapping relationship between the identifier of image layer data a and the storage path of image layer data a does not exist in its image database. If virtual machine B finds the identifier of image layer data a in the specified directory, it will not download image layer data a, so the mapping relationship between the identifier of image layer data a and the storage path of image layer data a will not be written into the image database of virtual machine B, and virtual machine B cannot run the container. Before querying the target image layer identifier in the specified directory, query the target image database first, so that when the target image layer identifier does not exist in the target image database but exists in the specified directory, the mapping relationship between the identifier of the target image layer data and the storage path of the target image layer data can be written into the target image database, thereby avoiding the above-mentioned situation where the container cannot run.
[0056] like Figure 3A The diagram shows a process diagram of a user creating a container. The container runtime component 330 installed on the physical machine 310 for creating a container 350 receives the instruction for creating a container sent by the user 340, and the instruction contains the image file identifier to be downloaded by the user. Then the container runtime component 330 forwards the instruction to the virtual machine 320 so that the virtual machine 320 executes the operation of downloading the container image. First, according to the image file identifier in the instruction, the image file 370 corresponding to the image file identifier is queried in the public image warehouse 360. The image file 370 includes at least one layer of image layer data, image layer data 1 (371), image layer data 2 (372) and image layer data 3 (373). After obtaining each layer of image layer identifier, each layer of image layer data is downloaded to obtain a complete image file 370, and finally each layer of the downloaded image layer data is placed in the container 350 for operation. Generally speaking, the component used to create a container is directly installed on the physical machine, but at the same time, the physical machine is at risk of being attacked. The security of the physical machine can be ensured by installing the component on a virtual machine. In one embodiment of the present specification, a virtual machine running at least one secure container is connected to a first virtual machine, and a component for creating a secure container is configured in the first virtual machine; before obtaining the target image layer identifier, it also includes: receiving an instruction to create a secure container sent by the component, so that the virtual machine obtains the target image layer identifier when responding to the instruction. Figure 3BThe figure shows a process of creating a secure container by a user according to an embodiment of the present specification. With containerd as a component for creating a container, containerd 380 installed on a virtual machine 300 for creating a container 350 receives a command for creating a container sent by a user 340, and forwards the command to a virtual machine 320 through an agent client 390 installed on a physical machine 310 to execute the above-mentioned operation of downloading a container image. The command includes an identifier of an image file to be downloaded by the user. The virtual machine 300 is different from the virtual machine 320 used by the user 340 to run the container 350.
[0057] In the aforementioned process of downloading the complete image file image, the downloaded manifest file, config file, and the compressed package of each layer file (image layer data) can be collectively referred to as content files and stored in the content directory maintained by the container runtime component. The identifiers of each content file will be stored in a file called contentstore. After downloading the target image layer data, you can also query whether there is a target image layer identifier in the content store or content directory to determine whether the target image layer data has been downloaded successfully. In one embodiment of the present specification, after downloading the target image layer data corresponding to the target image layer identifier, query whether there is a target image layer identifier in the content store, and the content store is used to store the target image layer identifier; when the target image layer identifier is not queried, query whether there is a target image layer identifier in the content directory, and the content directory is used to store the compressed package of the target image layer data; when the target image layer identifier is not queried, download the target image layer data corresponding to the target image layer identifier.
[0058] like Figure 4 FIG. 1 is a flowchart of a method for downloading a secure container image according to another embodiment of the present specification, comprising the following steps:
[0059] Step 401, obtaining the target image layer identifier;
[0060] Step 402, querying the target image database to see whether there is a target image layer identifier;
[0061] If the image layer identifier is found, step 408 is executed to obtain the next image layer identifier; if the image layer identifier is not found, step 403 is executed.
[0062] Step 403, querying whether there is target image layer data corresponding to the target image layer identifier in the specified directory;
[0063] If the image layer identifier is found, step 407 is executed; if the image layer identifier is not found, step 404 is executed.
[0064] Step 404, downloading the target image layer data corresponding to the target image layer identifier;
[0065] Step 405, decompress the target image layer data and convert the target image layer data into rafs format;
[0066] Step 406, storing the target image layer data converted into the rafs format in a specified directory;
[0067] Step 407, write the mapping relationship between the target image layer identifier and the storage path of the target image layer data into the target image database;
[0068] Step 408, obtaining the next image layer identifier.
[0069] Repeat the above steps 401-408 until all required target image layer data is obtained.
[0070] Corresponding to the embodiments of the aforementioned method, this specification also provides embodiments of a device and a terminal to which it is applied.
[0071] The embodiments of the device for downloading secure container image files in this specification can be applied to electronic devices. The device embodiments can be implemented by software, hardware, or a combination of software and hardware. Taking software implementation as an example, as a device in a logical sense, it is formed by the processor reading the corresponding computer program instructions in the non-volatile memory into the memory and running them. From the hardware level, if Figure 5 As shown in the figure, it is a hardware structure diagram of the electronic device where the device for downloading the secure container image file according to the embodiment of this specification is located, except Figure 5 In addition to the processor 510, memory 530, network interface 520, and non-volatile memory 540 shown, the electronic device where the device 531 is located in the embodiment may also include other hardware according to the actual function of the electronic device, which will not be described in detail.
[0072] like Figure 6 As shown, Figure 6 This is a block diagram of a device for downloading a secure container image file according to an exemplary embodiment of the present specification, which is applied to a virtual machine, in which at least one secure container is running, and the image file includes at least one layer of image layer data, and the device includes:
[0073] The acquisition module 610 is used to obtain the target image layer identifier;
[0074] A query module 620 is used to query whether there is target image layer data corresponding to the target image layer identifier in a specified directory, and the specified directory is used to store the image layer data downloaded by each virtual machine accessible to the same user;
[0075] A download module 630, configured to download the target image layer data when the target image layer data is not found;
[0076] The first storage module 640 is used to store the target image layer data in a specified directory;
[0077] The second storage module 650 is used to write the mapping relationship between the target image layer identifier and the storage path of the target image layer data into a target image database, where the target image database is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
[0078] In some device embodiments of the present specification, the query module is further configured to query whether the target image layer identifier exists in the target image database before querying whether the target image layer data corresponding to the target image layer identifier exists in the specified directory.
[0079] In some device embodiments of the present specification, the device further includes: a decompression module for decompressing the target image layer data; a separation module for separating the decompressed target image layer data into metadata and image data, wherein the metadata is used to characterize the storage structure of the image data.
[0080] In some device embodiments of the present specification, separating the decompressed target image layer data into metadata and image data includes: converting the decompressed target image layer data into a rafs format.
[0081] In some device embodiments of the present specification, the designated directory is created based on the virtiofs file system.
[0082] In some device embodiments of the present specification, a virtual machine is connected to a first virtual machine, and a component for creating a secure container is configured in the first virtual machine; the device also includes a receiving module for receiving an instruction for creating a secure container sent by the component, so that the virtual machine obtains a target image layer identifier when responding to the instruction.
[0083] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here.
[0084] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. A person of ordinary skill in the art can understand and implement it without paying creative labor.
[0085] Accordingly, this specification also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any of the foregoing method embodiments when executing the program. In addition, this specification also provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and the computer program is used to instruct related hardware to complete the method described in any of the foregoing method embodiments.
[0086] In addition, this specification also provides a distributed system, which includes multiple computer devices, and the computer devices include a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any of the above method embodiments when executing the program. Figure 7 FIG. 7 is a schematic diagram of a distributed system according to an embodiment of the present specification. The distributed system 700 is composed of multiple servers, including a server 710, a server 720, a server 730, a server 740, and a server 750. The servers are interconnected through a network 760 to provide services to the outside.
[0087] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0088] Those skilled in the art will readily appreciate other embodiments of the specification after considering the specification and practicing the inventions claimed herein. The specification is intended to cover any variations, uses, or adaptations of the specification that follow the general principles of the specification and include common knowledge or customary techniques in the art that are not claimed in the specification. The specification and examples are to be considered exemplary only, and the true scope and spirit of the specification are indicated by the claims.
[0089] It should be understood that the present description is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present description is limited only by the appended claims.
[0090] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.
Claims
1. A method for downloading a secure container image file, applied to each virtual machine running on a physical machine, wherein the physical machine can run virtual machines of multiple different users; Each of the virtual machines has an independent image database, and the image database is used to store the mapping relationship between the identifier of the image layer data downloaded by the virtual machine and the image layer data storage path; The shared file system on the physical machine creates a designated directory corresponding to each user, so that multiple virtual machines of the same user can access the designated directory of the user; At least one secure container is running in the virtual machine, the image file includes at least one layer of image layer data, and the method includes: Get the target image layer ID; Querying whether there is target image layer data corresponding to the target image layer identifier in a specified directory, wherein the specified directory is used to store image layer data downloaded by each virtual machine accessible to the same user; When the target image layer data is found, the target image layer data is obtained from the specified directory; When the target image layer data is not found, downloading the target image layer data; Storing the target image layer data in the specified directory; The mapping relationship between the target image layer identifier and the storage path of the target image layer data is written into a target image database, where the target image database is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
2. The method according to claim 1, before querying whether there is target image layer data corresponding to the target image layer identifier in the specified directory, further comprises: The target image database is queried to determine whether the target image layer identifier exists.
3. The method according to claim 1, before storing the target image layer data in the designated directory, further comprises: Decompressing the target image layer data; The decompressed target image layer data is separated into metadata and image data, wherein the metadata is used to characterize the storage structure of the image data.
4. According to the method of claim 3, separating the decompressed target image layer data into metadata and image data comprises: The decompressed target image layer data is converted into rafs format.
5. According to the method of claim 1, the designated directory is created based on the virtiofs file system.
6. The method according to claim 1, wherein the virtual machine is connected to a first virtual machine, wherein the first virtual machine is configured with a component for creating the secure container; Before obtaining the target image layer identifier, it also includes: An instruction to create the secure container is received from the component, so that the virtual machine obtains the target image layer identifier when responding to the instruction.
7. A device for downloading a secure container image file, applied to each virtual machine running on a physical machine, wherein the physical machine can run virtual machines of multiple different users; Each of the virtual machines has an independent image database, and the image database is used to store the mapping relationship between the identifier of the image layer data downloaded by the virtual machine and the image layer data storage path; The shared file system on the physical machine creates a designated directory corresponding to each user, so that multiple virtual machines of the same user can access the designated directory of the user; At least one secure container is running in the virtual machine, the image file includes at least one layer of image layer data, and the device includes: The acquisition module is used to obtain the target image layer identifier; A query module, used to query whether there is target image layer data corresponding to the target image layer identifier in a specified directory, wherein the specified directory is used to store image layer data downloaded by each virtual machine accessible to the same user; when the target image layer data is queried, the target image layer data is obtained from the specified directory; A download module, used for downloading the target image layer data when the target image layer data is not found; A first storage module, used to store the target image layer data in the specified directory; The second storage module is used to write the mapping relationship between the target image layer identifier and the storage path of the target image layer data into a target image database, and the target image database is used to store the mapping relationship between the downloaded target image layer identifier and the storage path of the target image layer data.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium storing a computer program, wherein the computer program is used to instruct related hardware to perform the method according to any one of claims 1 to 6.
10. A distributed system, comprising a plurality of computer devices, wherein the computer devices comprise a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Method, devices and system for obtaining mirror image in cloud environment
CN106487850A
Safe container operation method and device, mirror image data downloading method and device and storage medium
CN113886004A