A Kubernetes Component Configuration Method, Device, Equipment and Medium

By configuring the detection points and control logic of Kubelet and Docker components in the Kubernetes environment, the problem of difficult physical password machines to achieve conservation and utilization in the cloud computing environment is solved, and secure resource management and information protection are achieved.

CN114995956BActive Publication Date: 2025-05-30CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210706349.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-21
Publication Date
2025-05-30
Estimated Expiration
2042-06-21

AI Technical Summary

Technical Problem

It is difficult for traditional physical cryptographic machines to achieve features such as saving and utilization, on-demand allocation, flexible scheduling, automated deployment/upgrade in the cloud computing environment, while avoiding internal information leakage or destruction.

Method used

By establishing detection points and configuring control logic in Kubernetes' Kubelet component, the virtual password machine is prohibited from using external storage and performing remote operations; in the Docker component, the download of images from externally is prohibited, and the virtual password machine is provided with mirror management functions to complete the configuration of Kubernetes component.

Benefits of technology

It realizes that physical cryptographic machines can safely have the characteristics of economical utilization, on-demand allocation, flexible scheduling, automated deployment/upgrade in the cloud computing environment, and avoid internal information leakage or destruction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114995956B_ABST
    Figure CN114995956B_ABST
Patent Text Reader

Abstract

The present application discloses a method, apparatus, device and medium for configuring Kubernetes components, which relates to the technical fields of cloud computing and information security, and includes: establishing a first detection point in the Kubelet component of Kubernetes, and configuring a first control logic for the first detection point to prohibit the use of external storage for the virtual password machine through the first control logic; establishing a second detection point in the Kubelet component of Kubernetes, and configuring a second control logic for the second detection point to prohibit remote operations on the virtual password machine through the second control logic; establishing a third detection point in the Docker component of Kubernetes, and configuring a third control logic for the third detection point to prohibit the Docker component from downloading images externally and provide an image management function for the virtual password machine to complete the configuration of Kubernetes components. In this way, through the configuration of Kubernetes components in the present application, after the configured components are deployed to the physical password machine, the physical password machine can securely access Kubernetes and provide password services with the characteristics and advantages of Kubernetes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of cloud computing and information security, and particularly relates to a method, device, equipment and medium for configuring Kubernetes components. Background Art

[0002] Cloud computing is a pay-per-use model that provides available, convenient, on-demand network access to a configurable computing resource sharing pool (resources include networks, servers, storage, application software, services). These resources can be quickly provided with little management effort or little interaction with service providers.

[0003] A physical cipher machine is a hardware device that takes cipher technology as the core and provides secure key management and cipher operations for business systems. The business system realizes the confidentiality, integrity, validity and non-repudiation of data by invoking the cipher services provided by the physical cipher machine. On the physical cipher machine, a cipher service instance that provides the same services as the entity cipher machine, namely Virtual Security Module (VSM, virtual cipher machine), is created by using virtualization technology.

[0004] With the development and popularization of cloud computing technology, these business systems are gradually migrated to the cloud. By adopting cloud computing-related technologies, the conservation, on-demand allocation, elastic scheduling of resources, and the automated deployment / upgrade of business systems are realized. Correspondingly, these business systems require that the physical cipher machine can also have characteristics such as conservation, on-demand allocation, elastic scheduling, and automated deployment / upgrade. However, since traditional physical cipher machines are difficult to meet these requirements, and since physical cipher machines are cipher products and store keys and other sensitive information internally, it is an urgent problem in this field to require the physical cipher machine to realize characteristics such as conservation, on-demand allocation, elastic scheduling, and automated deployment / upgrade on the premise of avoiding the leakage or damage of internal information. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a method, device, equipment and medium for configuring Kubernetes components, so that the physical cipher machine can realize characteristics such as conservation, on-demand allocation, elastic scheduling, and automated deployment / upgrade on the premise of avoiding the leakage or damage of internal information. The specific solutions are as follows:

[0006] In a first aspect, the present application discloses a method for configuring Kubernetes components, including:

[0007] Establish a first detection point in the Kubelet component of Kubernetes and configure first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic;

[0008] Establish a second detection point in the Kubelet component of Kubernetes, and configure second control logic for the second detection point to prohibit remote operations on the virtual cipher machine through the second control logic;

[0009] Establish a third detection point in the Docker component of Kubernetes, and configure third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then provide an image management function for the virtual cipher machine to complete the configuration of the Kubernetes component.

[0010] Optionally, the prohibiting the use of external storage for the virtual cipher machine through the first control logic includes:

[0011] Through the first control logic, determine the storage location specified by the Kubernetes master when creating the virtual cipher machine based on the physical cipher machine, and control the first detection point to detect whether the storage location is external storage. If so, prohibit the creation of the virtual cipher machine and feedback corresponding error information to the Kubernetes master.

[0012] Optionally, the prohibiting remote operations on the virtual cipher machine through the second control logic includes:

[0013] Through the second control logic, obtain the command created by the Kubernetes carried in the Kubernetes master, and control the second detection point to detect whether the command is a remote operation on the virtual cipher machine. If so, prohibit the execution of the command and feedback corresponding error information to the Kubernetes master.

[0014] Optionally, the prohibiting the Docker component from downloading images externally through the third control logic includes:

[0015] Through the third control logic, control the third detection point to detect whether the Docker component downloads images externally. If so, prohibit the process of the Docker component from downloading images externally.

[0016] Optionally, the providing an image management function for the virtual cipher machine includes:

[0017] Obtain the currently imported image file and perform signature verification on the image file;

[0018] If the verification passes, import the image file into the image library in the physical cipher machine.

[0019] Optionally, providing an image management function for the virtual cipher machine, after completing the configuration of the Kubernetes components, further includes:

[0020] Deploying the configured Kubernetes components to a physical cipher machine, and connecting the physical cipher machine to Kubernetes.

[0021] Optionally, after deploying the configured Kubernetes components to a physical cipher machine and connecting the physical cipher machine to Kubernetes, further includes:

[0022] Using Kubernetes to schedule the physical cipher machine, so that the physical cipher machine generates the virtual cipher machine based on the image file in the image library.

[0023] In a second aspect, the present application discloses a Kubernetes component configuration device, including:

[0024] A first configuration module, used to establish a first detection point in the Kubelet component of Kubernetes, and configure a first control logic for the first detection point, so as to prohibit the use of external storage for the virtual cipher machine through the first control logic;

[0025] A second configuration module, used to establish a second detection point in the Kubelet component of Kubernetes, and configure a second control logic for the second detection point, so as to prohibit remote operations on the virtual cipher machine through the second control logic;

[0026] A third configuration module, used to establish a third detection point in the Docker component of Kubernetes, and configure a third control logic for the third detection point, so as to prohibit the Docker component from downloading images externally through the third control logic, and then provide an image management function for the virtual cipher machine to complete the configuration of the Kubernetes components.

[0027] In a third aspect, the present application discloses an electronic device, including:

[0028] A memory, used to store a computer program;

[0029] A processor, used to execute the computer program to implement the foregoing disclosed Kubernetes component configuration method.

[0030] Fourthly, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the foregoing disclosed Kubernetes component configuration method is implemented.

[0031] It can be seen that the present application discloses a Kubernetes component configuration method, including: establishing a first detection point in the Kubelet component of Kubernetes and configuring first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic; establishing a second detection point in the Kubelet component of Kubernetes and configuring second control logic for the second detection point to prohibit remote operations on the virtual cipher machine through the second control logic; establishing a third detection point in the Docker component of Kubernetes and configuring third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then providing an image management function for the virtual cipher machine to complete the Kubernetes component configuration. In this way, since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, the present application configures the Kubernetes components so that after the configured components are deployed to the physical cipher machine, the physical cipher machine can securely access Kubernetes and provide cipher services with the characteristics and advantages of Kubernetes. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0033] Figure 1 It is a flowchart of a Kubernetes component configuration method disclosed in the present application;

[0034] Figure 2 It is a flowchart of a specific Kubernetes component configuration method disclosed in the present application;

[0035] Figure 3 It is a schematic structural diagram of connecting a physical cipher machine to Kubernetes disclosed in the present application;

[0036] Figure 4Schematic diagram of a Kubernetes component configuration device disclosed in this application;

[0037] Figure 5 Structural diagram of an electronic device disclosed in this application. Detailed implementation manners

[0038] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0039] The business system requires that the physical cipher machine can have characteristics such as resource conservation, on-demand allocation, elastic scheduling, automated deployment / upgrade, etc. However, it is difficult for traditional physical cipher machines to meet these requirements. Moreover, since the physical cipher machine is a cipher product and stores keys and other sensitive information internally, it is necessary to have characteristics such as resource conservation, on-demand allocation, elastic scheduling, automated deployment / upgrade, etc. on the premise of preventing internal information from being leaked or damaged.

[0040] Therefore, an embodiment of this application proposes a Kubernetes component configuration solution, which can enable the physical cipher machine to have characteristics such as resource conservation, on-demand allocation, elastic scheduling, automated deployment / upgrade, etc. on the premise of preventing internal information from being leaked or damaged.

[0041] An embodiment of this application discloses a Kubernetes component configuration method. As shown in Figure 1 below, the method includes:

[0042] Step S11: Establish a first detection point in the Kubelet component of Kubernetes and configure a first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic.

[0043] It should be noted that a Pod is a set of closely related containers and is the basic unit of Kubernetes scheduling. They share IPC (Inter-Process Communication), Network, and UTC namespace. Kubernetes can use external storage when configuring a Pod and map the external storage to a specified directory of the Pod. Different from a Pod, sensitive information is stored inside the virtual cipher machine. Therefore, if the directory storing sensitive information of the virtual cipher machine is set as external storage, the sensitive information can be found in the external storage. Although sensitive information such as keys is in ciphertext form, if such sensitive information appears in the external storage, it will also increase the risk of leakage. Therefore, in this embodiment, when creating a virtual cipher machine, it is necessary to prohibit configuring external storage for the virtual cipher machine. Specifically, a first detection point is established in the Kubelet component of Kubernetes, and a first control logic is configured for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic. In this way, it can prevent the leakage of sensitive data caused by accessing external storage.

[0044] Step S12: Establish a second detection point in the Kubelet component of Kubernetes, and configure a second control logic for the second detection point to prohibit performing remote operations on the virtual cipher machine through the second control logic.

[0045] It should be noted that Kubernetes provides a series of commands for Kubernetes administrators to remotely operate on Pods, such as: copying data from a Pod, copying data to a Pod, executing commands in a Pod, etc. For a physical cipher machine, if Kubernetes administrators are allowed to execute the above commands, the administrators can copy or damage the sensitive information inside the virtual cipher machine. Therefore, in this embodiment, the present application restricts the execution of commands such as exec / run / cp / attach by configuring the Kubelet component. Specifically, a second detection point is established in the Kubelet component of Kubernetes, and a second control logic is configured for the second detection point to prohibit performing remote operations on the virtual cipher machine through the second control logic. In this way, it can prevent malicious operations by administrators.

[0046] Step S13: Establish a third detection point in the Docker component of Kubernetes, and configure a third control logic for the third detection point to prohibit the Docker component from downloading images from the outside, and then provide an image management function for the virtual cipher machine to complete the configuration of Kubernetes components.

[0047] It should be noted that, by default, the Docker (application container engine) component is used as the container implementation in Kubernetes. Specifically, Kubernetes is responsible for scheduling, and finally the Docker component generates Pods. For a physical cryptographic machine, as a Node node accessing Kubernetes, Docker is also used internally to generate virtual cryptographic machines. When creating a virtual cryptographic machine and downloading an image from the outside, Docker will download the image externally. However, since malicious images may be downloaded from the outside, it may lead to the theft or damage of sensitive data inside the physical cryptographic machine. Therefore, the physical cryptographic machine can restrict the execution of malicious images in the physical cryptographic machine from two dimensions. On the one hand, it is necessary to prohibit the Docker component from downloading images from the outside. Specifically, a third detection point is established in the Docker component of Kubernetes, and a third control logic is configured for the third detection point to prohibit the Docker component from downloading images from the outside through the third control logic. On the other hand, an image management function is provided for the virtual cryptographic machine to allow the import of images with built-in signatures to complete the configuration of the Kubernetes component. In this way, the theft or damage of sensitive data inside the physical cryptographic machine can be avoided.

[0048] In this embodiment, after completing the configuration of the Kubernetes component, it is necessary to deploy the configured Kubernetes component to the physical cryptographic machine, so that the physical cryptographic machine can be securely connected to Kubernetes. Since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, in this application, by configuring the Kubernetes component, after deploying the configured component to the physical cryptographic machine, the physical cryptographic machine can be securely connected to Kubernetes and provide password services with the characteristics and advantages of Kubernetes. Specifically, after the physical cryptographic machine is connected to Kubernetes, the Kubernetes can be used to schedule the physical cryptographic machine, so that the physical cryptographic machine can generate the virtual cryptographic machine based on the image file in the image library, and the virtual cryptographic machine provides a password service instance similar to the service of the physical cryptographic machine.

[0049] It can be seen that the present application discloses a method for configuring Kubernetes components, including: establishing a first detection point in the Kubelet component of Kubernetes and configuring first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic; establishing a second detection point in the Kubelet component of Kubernetes and configuring second control logic for the second detection point to prohibit remote operations on the virtual cipher machine through the second control logic; establishing a third detection point in the Docker component of Kubernetes and configuring third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then providing an image management function for the virtual cipher machine to complete the configuration of Kubernetes components. In this way, since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, the present application configures the Kubernetes components so that after the configured components are deployed to the physical cipher machine, the physical cipher machine can securely access Kubernetes and provide cipher services with the characteristics and advantages of Kubernetes.

[0050] The embodiment of the present application discloses a specific method for configuring Kubernetes components. Refer to Figure 2 as shown, this method includes:

[0051] Step S21: Establish a first detection point in the Kubelet component of Kubernetes and configure first control logic for the first detection point to determine the storage location specified by the KuberNetes master when creating a virtual cipher machine based on the physical cipher machine through the first control logic, and control the first detection point to detect whether the storage location is external storage. If so, prohibit the creation of the virtual cipher machine and feedback corresponding error information to the KuberNetes master.

[0052] In this embodiment, the first control logic is used to control the first detection point to detect whether the storage location is external storage. Specifically, if so, prohibit the creation of the virtual cipher machine and feedback corresponding error information to the KuberNetes master.

[0053] Step S22: Establish a second detection point in the Kubelet component of Kubernetes, and configure second control logic for the second detection point, so as to, through the second control logic, obtain the command created by Kubernetes carried in the Kubernetes master, and control the second detection point to detect whether the command is a remote operation on the virtual cipher machine. If so, prohibit the execution of the command and feedback corresponding error information to the Kubernetes master.

[0054] In this embodiment, the second control logic is used to control the second detection point to detect whether the command is a remote operation on the virtual cipher machine. Specifically, if so, prohibit the execution of the command and feedback corresponding error information to the Kubernetes master.

[0055] Step S23: Establish a third detection point in the Docker component of Kubernetes, and configure third control logic for the third detection point, so as to, through the third control logic, control the third detection point to detect whether the Docker component downloads an image from the outside. If so, prohibit the process of the Docker component from downloading the image from the outside, then obtain the currently imported image file, and perform signature verification on the image file. If the verification passes, import the image file into the image library in the physical cipher machine, so as to complete the configuration of the Kubernetes component.

[0056] In this embodiment, the third control logic is used to control the third detection point to detect whether the Docker component downloads an image from the outside. Specifically, if so, prohibit the process of the Docker component from downloading the image from the outside. In addition, this embodiment provides a secure image management function for the physical cipher machine. Specifically, obtain the currently imported image file, and perform signature verification on the image file. If the verification passes, import the image file into the image library in the physical cipher machine to complete the configuration of the Kubernetes component.

[0057] It can be seen that the present application discloses a method for configuring Kubernetes components, including: establishing a first detection point in the Kubelet component of Kubernetes and configuring first control logic for the first detection point, so as to determine, through the first control logic, the storage location specified by the Kubernetes master when creating a virtual cipher machine based on a physical cipher machine, and controlling the first detection point to detect whether the storage location is external storage. If so, creating a virtual cipher machine is prohibited, and corresponding error information is fed back to the Kubernetes master; establishing a second detection point in the Kubelet component of Kubernetes and configuring second control logic for the second detection point, so as to obtain, through the second control logic, the command carried in the Kubernetes master created by Kubernetes, and controlling the second detection point to detect whether the command is to perform a remote operation on the virtual cipher machine. If so, executing the command is prohibited, and corresponding error information is fed back to the Kubernetes master; establishing a third detection point in the Docker component of Kubernetes and configuring third control logic for the third detection point, so as to control the third detection point to detect whether the Docker component downloads an image from the outside. If so, the process of the Docker component downloading an image from the outside is prohibited, then the currently imported image file is obtained, and the image file is subjected to signature verification. If the verification passes, the image file is imported into the image library in the physical cipher machine, so as to complete the configuration of the Kubernetes components. In this way, since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, the present application configures the Kubernetes components, so that after the configured components are deployed to the physical cipher machine, the physical cipher machine can securely access Kubernetes and provide cipher services with the characteristics and advantages of Kubernetes.

[0058] Figure 3 It is a schematic structural diagram of connecting a physical cipher machine to Kubernetes disclosed in the present application.

[0059] It should be noted that Kubernetes is an open-source container cluster management system created by Google in 2014 and is the open-source version of Google's large-scale container management technology Borg over the past decade. It is built on top of Docker technology and provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications. Kubernetes has the functions of quickly deploying and expanding applications, seamlessly docking new application functions, saving resources, and optimizing hardware resources. A Kubernetes cluster consists of two types of nodes, Master and Node. The Node node is the actual host where the Pod runs, which can be a physical machine or a virtual machine. To manage the Pod, at least the Container, Runtime (such as Docker), Kubelet, and Kube-proxy services need to run on each Node node.

[0060] Figure 3 The components involved specifically include: physical cryptographic hardware, Kubernetes Master series components, the kubelet component after security transformation, the kube-proxy component, and Docker. The main functions of each component are described as follows:

[0061] (1) Physical cryptographic hardware: includes CPU, memory, cryptographic card, hard disk, motherboard, network card, etc., and provides key security management and cryptographic operation services.

[0062] (2) Kubernetes Master series components: are the overall control center of Kubernetes and are responsible for controlling and scheduling all resources in the cluster.

[0063] (3) The kubelet after security transformation: is deployed in the physical cryptographic machine and is responsible for securely connecting the physical cryptographic machine as a Node node to Kubernetes, receiving instructions from the Kubernetes Master, and finally scheduling Docker to generate and manage VSM instances.

[0064] (4) The kube-proxy component: is deployed in the physical cryptographic machine and is responsible for generating corresponding network policies on the physical cryptographic machine according to the Pod and Service objects generated by the Master.

[0065] (5) Docker: is an open-source application container engine that allows developers to package their applications and dependencies into a portable image and then publish it to any popular Linux or Windows machine, and can also achieve virtualization. It is deployed in the physical cryptographic machine and is responsible for generating and managing VSM instances.

[0066] In this application, by configuring the Kubernetes components, after the configured components are deployed to the physical cipher machine, the physical cipher machine can be connected to Kubernetes as a Node node, and then Kubernetes can schedule the physical cipher machine to generate a VSM (the VSM can be regarded as a Pod). In this way, since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, after the physical cipher machine is securely connected to Kubernetes, it can provide cipher services with the characteristics and advantages of Kubernetes.

[0067] Correspondingly, the embodiment of this application also discloses a Kubernetes component configuration device. Refer to Figure 4 as shown, this device includes:

[0068] The first configuration module 11 is used to establish a first detection point in the Kubelet component of Kubernetes and configure first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic;

[0069] The second configuration module 12 is used to establish a second detection point in the Kubelet component of Kubernetes and configure second control logic for the second detection point to prohibit remote operations on the virtual cipher machine through the second control logic;

[0070] The third configuration module 13 is used to establish a third detection point in the Docker component of Kubernetes and configure third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then provide an image management function for the virtual cipher machine to complete the configuration of Kubernetes components.

[0071] Among them, for the more specific working processes of the above-mentioned various modules, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated here.

[0072] As can be seen, the present application discloses a method for configuring Kubernetes components, including: establishing a first detection point in the Kubelet component of Kubernetes and configuring first control logic for the first detection point to prohibit the use of external storage for the virtual password machine through the first control logic; establishing a second detection point in the Kubelet component of Kubernetes and configuring second control logic for the second detection point to prohibit remote operations on the virtual password machine through the second control logic; establishing a third detection point in the Docker component of Kubernetes and configuring third control logic for the third detection point to prohibit the Docker component from downloading images from the outside, and then providing an image management function for the virtual password machine to complete the configuration of Kubernetes components. In this way, since Kubernetes is an open-source container cluster management system that provides services such as resource scheduling, deployment and operation, service discovery, and scaling for containerized applications, the present application configures the Kubernetes components so that after the configured components are deployed to the physical password machine, the physical password machine can securely access Kubernetes and provide password services with the characteristics and advantages of Kubernetes.

[0073] Further, the embodiment of the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure should not be considered as any limitation on the scope of use of the present application.

[0074] Figure 5 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the method for configuring Kubernetes components disclosed in any of the foregoing embodiments.

[0075] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0076] In addition, as a carrier for resource storage, the memory 22 can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, data 223, etc. The data 223 can include various kinds of data. The storage method can be transient storage or permanent storage.

[0077] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of implementing the Kubernetes component configuration method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs capable of performing other specific tasks.

[0078] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the foregoing disclosed Kubernetes component configuration method is implemented.

[0079] For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0080] The various embodiments in this application are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for related parts.

[0081] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0082] The steps of the methods or algorithms described in combination with the embodiments disclosed in this document can be implemented directly in hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0083] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0084] The above has introduced in detail a method, device, equipment, and storage medium for configuring Kubernetes components provided by this application. Specific examples are used in this document to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A method for configuring Kubernetes components, characterized in that, it includes: Establish a first detection point in the Kubelet component of Kubernetes, and configure first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic; Establish a second detection point in the Kubelet component of Kubernetes, and configure second control logic for the second detection point to prohibit performing remote operations on the virtual cipher machine through the second control logic; Establish a third detection point in the Docker component of Kubernetes, and configure third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then provide an image management function for the virtual cipher machine to complete the configuration of Kubernetes components.

2. The method for configuring Kubernetes components according to claim 1, characterized in that, The prohibition of using external storage for the virtual cipher machine through the first control logic includes: Through the first control logic, determine the storage location specified by the Kubernetes master when creating the virtual cipher machine based on the physical cipher machine, and control the first detection point to detect whether the storage location is external storage. If so, prohibit creating the virtual cipher machine and feedback corresponding error information to the Kubernetes master.

3. The method for configuring Kubernetes components according to claim 1, characterized in that, The prohibition of performing remote operations on the virtual cipher machine through the second control logic includes: Through the second control logic, obtain the command created by the Kubernetes carried in the Kubernetes master, and control the second detection point to detect whether the command is to perform a remote operation on the virtual cipher machine. If so, prohibit executing the command and feedback corresponding error information to the Kubernetes master.

4. The method for configuring Kubernetes components according to claim 1, characterized in that, The prohibition of the Docker component from downloading images externally through the third control logic includes: Through the third control logic, control the third detection point to detect whether the Docker component downloads images externally. If so, prohibit the process of the Docker component from downloading images externally.

5. The method for configuring Kubernetes components according to any one of claims 1 to 4, characterized in that, The providing of the image management function for the virtual cipher machine includes: Obtain the currently imported image file and perform signature verification on the image file; If the verification passes, import the image file into the image library in the physical cipher machine.

6. The method for configuring Kubernetes components according to claim 5, characterized in that, Providing an image management function for the virtual cipher machine, after completing the configuration of Kubernetes components, further includes: Deploying the configured Kubernetes components to a physical cipher machine, and connecting the physical cipher machine to Kubernetes.

7. The Kubernetes component configuration method according to claim 6, characterized in that, after deploying the configured Kubernetes components to a physical cipher machine and connecting the physical cipher machine to Kubernetes, further includes: Using Kubernetes to schedule the physical cipher machine, so that the physical cipher machine generates the virtual cipher machine based on the image files in the image library.

8. A Kubernetes component configuration device, characterized in that, includes: A first configuration module, configured to establish a first detection point in the Kubelet component of Kubernetes and configure first control logic for the first detection point to prohibit the use of external storage for the virtual cipher machine through the first control logic; A second configuration module, configured to establish a second detection point in the Kubelet component of Kubernetes and configure second control logic for the second detection point to prohibit performing remote operations on the virtual cipher machine through the second control logic; A third configuration module, configured to establish a third detection point in the Docker component of Kubernetes and configure third control logic for the third detection point to prohibit the Docker component from downloading images externally, and then provide an image management function for the virtual cipher machine to complete the configuration of Kubernetes components.

9. An electronic device, characterized in that, includes: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the Kubernetes component configuration method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, configured to store a computer program; wherein, when the computer program is executed by a processor, it implements the Kubernetes component configuration method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Password display method and mobile terminal

    CN106503507A

  • Node management method and device, monitoring node and storage medium

    CN114500538A