A software authorization method and system compatible with different deployment environments

By adjusting the deployment script and using environment variables to obtain host feature information, and performing software authorization verification, the problem that traditional authorization methods cannot adapt to multiple deployment environments is solved, and unified authorization verification and multi-environment compatibility is achieved.

CN115391753BActive Publication Date: 2025-05-23CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211108631.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-13
Publication Date
2025-05-23
Estimated Expiration
2042-09-13

AI Technical Summary

Technical Problem

Traditional software authorization methods cannot adapt to multiple deployment environments, especially in container cloud platform environments based on kubernetes platform, which cannot meet the authorization needs of microservice clusters.

Method used

By adjusting different environment deployment scripts/mechanisms, using environment variables to obtain host feature information, and comparing it with certificate information, and performing software authorization verification. Just generate an authorization certificate for one deployment environment to realize software license verification for all microservices in the system, and is compatible with multiple deployment environments.

Benefits of technology

It realizes unified software authorization verification and compatibility with multiple deployment environments, meets the authorization needs of microservice clusters, and improves the flexibility and universality of the authorization mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115391753B_ABST
    Figure CN115391753B_ABST
Patent Text Reader

Abstract

The present invention relates to a software authorization method and system compatible with different deployment environments, belonging to the field of software authorization technology. The method comprises: generating a digital certificate according to an asymmetric encryption algorithm and content containing software authorization information; packaging the digital certificate into various services of the software system, and adding corresponding code logic; deploying services for different deployment environments, the deployment environments including virtual machines or cloud hosts, container environments, and container cloud platform environments; when the service is started, executing the code logic to obtain host information and information of the digital certificate, and performing digital certificate verification. The method only needs to generate an authorization certificate for one deployment environment, so that all microservices in the system can verify the software license, and realize unified software authorization verification and compatibility of software authorization with multiple deployment environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of software authorization, and in particular relates to a software authorization method and system compatible with different deployment environments. Background Art

[0002] The deployment and operation environment of current software systems is becoming increasingly diversified and clustered, from more traditional virtual machines (including virtual machines in local computer rooms and cloud hosts on cloud platforms, etc.), to docker container environments running on virtual machines, and then to container cloud platform environments based on the kubernetes platform. Software systems have also evolved from the earliest single services to complex systems composed of many microservices, which generally need to be deployed and run in clusters composed of multiple virtual machines.

[0003] The traditional software authorization method based on a single virtual machine is not flexible and universal in this context and cannot meet the authorization requirements of various environments. Especially in the container cloud platform environment based on the Kubernetes platform, services are often scheduled to different host nodes or multiple instances are created for capacity expansion. This scenario cannot be met by the traditional single software authorization mechanism.

[0004] The existing software authorization method generally generates a digital certificate for the characteristic information of a single host. This method is not suitable for the current microservice cluster deployment model. Many software systems are deployed on dozens of virtual machine clusters, and each microservice will be scheduled to different host nodes as the business adjusts. Therefore, there is no binding relationship between a single host and a specific service, and it is impossible to use the traditional model to generate a digital certificate.

[0005] At the same time, many software systems support deployment in multiple environments, namely virtual machines, container environments, and container cloud platform environments. Traditional authorization models cannot support or be compatible with these deployment environments. If certificates are generated separately for each environment and different verification modules are developed, universality is lost. In fact, users may rotate or use multiple deployment environment modes simultaneously in the same host cluster according to their own needs, so a universal authorization certificate and verification mode are needed. Summary of the invention

[0006] The main purpose of the present invention is to overcome the shortcomings and deficiencies of the prior art and provide a software authorization method and system that is compatible with different deployment environments. By adjusting the deployment scripts / mechanisms of different environments, the host feature information is obtained by using environment variables, and then compared with the certificate information to perform software authorization verification. It only needs to generate an authorization certificate for one deployment environment to enable all microservices in the system to verify the software license, thereby achieving unified software authorization verification and software authorization compatibility with multiple deployment environments.

[0007] According to one aspect of the present invention, the present invention provides a software authorization method compatible with different deployment environments, the method comprising:

[0008] S1: Generate a digital certificate based on an asymmetric encryption algorithm and content containing software authorization information; package the digital certificate into various services of the software system and add corresponding code logic;

[0009] S2: Deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments;

[0010] S3: When the service is started, the code logic is executed to obtain the host information and the information of the digital certificate, and perform digital certificate verification.

[0011] Preferably, generating a digital certificate according to an asymmetric encryption algorithm and content containing software authorization information; packaging the digital certificate into various services of the software system, and adding corresponding code logic comprises:

[0012] A key pair is generated using an asymmetric encryption algorithm and saved in a private key library file. The private key is used to digitally sign the content containing authorization information and generate a digital certificate. The public key and the generated digital certificate are packaged into various services of the software system, and corresponding code logic is added; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node.

[0013] Preferably, the deployment of services for different deployment environments includes:

[0014] If the deployment environment is a virtual machine or cloud host, start it through the command line or script;

[0015] If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service;

[0016] If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

[0017] Preferably, when the service is started, executing the code logic to obtain the host information and the information of the digital certificate, and performing digital certificate verification includes:

[0018] When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

[0019] Preferably, the method further comprises:

[0020] After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

[0021] According to another aspect of the present invention, the present invention further provides a software authorization system compatible with different deployment environments, the system comprising:

[0022] A generation module, used to generate a digital certificate according to an asymmetric encryption algorithm and content containing software authorization information; package the digital certificate into various services of the software system, and add corresponding code logic;

[0023] A deployment module is used to deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments;

[0024] The verification module is used to execute the code logic to obtain the host information and the digital certificate information when the service is started, and perform digital certificate verification.

[0025] Preferably, the generation module generates a digital certificate according to an asymmetric encryption algorithm and the content containing software authorization information; packages the digital certificate into each service of the software system, and adds corresponding code logic including:

[0026] A key pair is generated using an asymmetric encryption algorithm and saved in a private key library file. The private key is used to digitally sign the content containing authorization information and generate a digital certificate. The public key and the generated digital certificate are packaged into various services of the software system, and corresponding code logic is added; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node.

[0027] Preferably, the deployment module performs service deployment for different deployment environments including:

[0028] If the deployment environment is a virtual machine or cloud host, start it through the command line or script;

[0029] If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service;

[0030] If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

[0031] Preferably, when the service is started, the verification module executes the code logic to obtain the host information and the information of the digital certificate, and the digital certificate verification includes:

[0032] When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

[0033] Preferably, the verification module is also used for:

[0034] After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

[0035] Beneficial effect: The present invention adjusts the deployment scripts / mechanisms of different environments, uses environment variables to obtain host feature information, and then compares it with the certificate information to perform software authorization verification. It only needs to generate an authorization certificate for one deployment environment to enable all microservices in the system to verify the software license, thereby achieving unified software authorization verification and software authorization compatibility with multiple deployment environments.

[0036] The features and advantages of the present invention will become clear through reference to the following drawings and detailed description of specific embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a flowchart of software authorization method compatible with different deployment environments;

[0038] Figure 2 It is a schematic diagram of a software authorization system that is compatible with different deployment environments. DETAILED DESCRIPTION

[0039] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0040] Example 1

[0041] Figure 1 This is a flowchart of a software authorization method that is compatible with different deployment environments. Figure 1 As shown, the present invention provides a software authorization method compatible with different deployment environments, the method comprising:

[0042] S1: Generate a digital certificate based on an asymmetric encryption algorithm and content containing software authorization information; package the digital certificate into various services of the software system and add corresponding code logic;

[0043] S2: Deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments;

[0044] S3: When the service is started, the code logic is executed to obtain the host information and the information of the digital certificate, and perform digital certificate verification.

[0045] This embodiment adjusts the deployment scripts / mechanisms for different environments, uses environment variables to obtain host feature information, and then compares it with the certificate information to perform software authorization verification. It only needs to generate an authorization certificate for one deployment environment to enable all microservices in the system to verify the software license, thereby achieving unified software authorization verification and software authorization compatibility with multiple deployment environments.

[0046] Preferably, generating a digital certificate according to an asymmetric encryption algorithm and content containing software authorization information; packaging the digital certificate into various services of the software system, and adding corresponding code logic comprises:

[0047] A key pair is generated using an asymmetric encryption algorithm and saved in a private key library file. The private key is used to digitally sign the content containing authorization information and generate a digital certificate. The public key and the generated digital certificate are packaged into various services of the software system, and corresponding code logic is added; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node.

[0048] Specifically, this step includes:

[0049] 1. Key pair generation

[0050] First, use the keytool tool to generate a key pair using an asymmetric encryption algorithm and save it in the private key library file privateKeys.keystore, then export the certificate in the private key library to a file certfile.cer, and finally import this certificate file into the public key library file publicCerts.store.

[0051] 2. Digital certificate generation

[0052] The authorized party retains the private key and uses the private key to digitally sign the license content containing the authorization information (including the validity period of the software license, the IP address list and MAC address list of the virtual machine / container host / container cloud platform node) and generate a digital certificate license.lic. Here, you can use an open source dependency package such as truelicense to generate the certificate.

[0053] 3. Introduction of digital certificates

[0054] Package the public key library file publicCerts.store and the generated digital certificate license.lic into each microservice of the software system (for example: springboot service demo-server.war), and add corresponding code logic to load the digital certificate when the service starts and use the public key to verify the validity of the certificate.

[0055] Preferably, the deployment of services for different deployment environments includes:

[0056] If the deployment environment is a virtual machine or cloud host, start it through the command line or script;

[0057] If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service;

[0058] If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

[0059] Specifically, this step uses different methods and mechanisms to deploy services for different deployment environments, including:

[0060] A. The deployment environment is a virtual machine or cloud host: The service runs directly on the virtual machine and is generally started through the command line or script. This deployment method does not require adjustment.

[0061] B. Deployment environment is container environment: The service is built as a docker image and the docker environment is installed on the host. Generally, a script or deployment tool is used to start the docker image to run the service. This deployment method requires adding environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host respectively. The specific values ​​are obtained dynamically at startup. Taking the centos7.6 host as an example, here you can first obtain the IP address and MAC address of the host through commands in the startup script, and then specify the container environment variables and assign values ​​through the -e option. For example: docker run–e DOCKER_NODE_IP=$(ip r|awk' / default / {print$3}')-e DOCKER_NODE_MAC=$(iplink show eth0|awk' / ether / {print$2}').

[0062] Usually, general software products will be packaged and provide their own deployment tools, which will improve user usability while shielding the authorization verification details, which is beneficial to the confidentiality and reliability of the authorization mechanism. Therefore, this model is recommended.

[0063] C. The deployment environment is a container cloud platform environment: The service is built as a docker image and a container cloud platform environment based on the kubernetes platform is built on a virtual machine cluster. Generally, deployment tools or deployment platforms are used to create and schedule services. This deployment method requires adding environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively. The specific values ​​are dynamically obtained at startup. Taking the centos7.6 host as an example, use the helm tool to deploy the k8s service, modify the corresponding yaml file in the helm script, dynamically obtain the host IP through the pod status data field and add the environment variable K8S_NODE_IP, for example:

[0064] containers:

[0065] -name:demo-server

[0066] image:demo-server:1.0

[0067] env:

[0068] -name:K8S_NODE_IP

[0069] valueFrom:

[0070] fieldRef:

[0071] apiVersion:v1

[0072] fieldPath:status.hostIP

[0073] At the same time, determine the file location of the network card address and mount it to the Pod using the read-only hostPath method, for example:

[0074] containers:

[0075] -name:demo-server

[0076] image:demo-server:1.0

[0077] volumeMounts:

[0078] -name:k8s-node-mac

[0079] mountPath: / root / k8s-node-mac

[0080] readOnly:true

[0081] volumes:

[0082] -name:k8s-node-mac

[0083] hostPath:

[0084] type:File

[0085] path: / sys / class / net / eth0 / address

[0086] In addition, read the content of the mounted file in the startup script specified by the entrypoint in the Dockerfile that builds the image and assign it to the environment variable K8S_NODE_MAC, for example:

[0087] export K8S_NODE_MAC=`cat / root / k8s-node-mac`

[0088] Preferably, when the service is started, executing the code logic to obtain the host information and the information of the digital certificate, and performing digital certificate verification includes:

[0089] When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

[0090] Specifically, when the service is started, the added code logic is executed, the digital certificate is loaded and verified with the public key, and the software authorization information (including the validity period of the software license, the IP address list and MAC address list of the virtual machine / container host / container cloud platform node) is obtained. Then, the environment to which it belongs is determined based on the environment variables, and the IP address and MAC address of the host machine are obtained, and compared with the software authorization information, including determining whether the current time is within the validity period of the license. After all requirements are met, the service is allowed to start. Otherwise, the service startup is terminated.

[0091] When comparing the host information and digital certificate information, judge in turn according to the environment variables, and give priority to using K8S_NODE_IP and K8S_NODE_MAC for comparison. If they do not exist, use DOCKER_NODE_IP and K8S_DOCKER_MAC for comparison. If they do not exist, it means that the current environment is a pure virtual machine environment. Use code logic to call system commands to obtain the host's IP address and MAC address for comparison.

[0092] Preferably, the method further comprises:

[0093] After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

[0094] Specifically, after the service is started, each user request (interface call) is intercepted and checked to see if the current certificate is still valid. If it is expired, the current request is terminated and an error message is returned.

[0095] This embodiment generates a digital certificate for a host cluster in a user deployment environment. As long as the service is deployed in the host cluster, it can be verified and used normally. This embodiment adjusts the deployment scripts / mechanisms of different environments, uses environment variables to obtain host feature information, and then compares it with the certificate information to achieve a unified authorization verification logic.

[0096] Example 2

[0097] Figure 2 This is a schematic diagram of a software authorization system that is compatible with different deployment environments. Figure 2As shown, the present invention also provides a software authorization system compatible with different deployment environments, the system comprising:

[0098] The generation module 201 is used to generate a digital certificate according to an asymmetric encryption algorithm and the content containing software authorization information; package the digital certificate into each service of the software system, and add corresponding code logic;

[0099] A deployment module 202 is used to deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments;

[0100] The verification module 203 is used to execute the code logic to obtain the host information and the digital certificate information when the service is started, and perform digital certificate verification.

[0101] Preferably, the generating module 201 generates a digital certificate according to an asymmetric encryption algorithm and the content including software authorization information; packages the digital certificate into each service of the software system, and adds corresponding code logic including:

[0102] A key pair is generated using an asymmetric encryption algorithm and saved in a private key library file. The private key is used to digitally sign the content containing authorization information and generate a digital certificate. The public key and the generated digital certificate are packaged into various services of the software system, and corresponding code logic is added; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node.

[0103] Preferably, the deployment module 202 performs deployment of services for different deployment environments including:

[0104] If the deployment environment is a virtual machine or cloud host, start it through the command line or script;

[0105] If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service;

[0106] If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

[0107] Preferably, when the service is started, the verification module 203 executes the code logic to obtain the host information and the information of the digital certificate, and performs digital certificate verification including:

[0108] When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

[0109] Preferably, the verification module 203 is further used for:

[0110] After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

[0111] The specific implementation process of the functions realized by each module in this embodiment 2 is the same as the implementation process of each step in embodiment 1, and will not be repeated here.

[0112] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. All equivalent structural changes made by using the contents of the present invention specification and drawings under the concept of the present invention, or directly / indirectly applied in other related technical fields are included in the patent protection scope of the present invention.

Claims

1. A software authorization method compatible with different deployment environments, characterized in that: The method comprises: S1: Generate a digital certificate based on an asymmetric encryption algorithm and content containing software authorization information; package the digital certificate into various services of the software system and add corresponding code logic; S2: Deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments; S3: When the service is started, the code logic is executed to obtain the host information and the information of the digital certificate, and to perform digital certificate verification; The steps of generating a digital certificate based on an asymmetric encryption algorithm and the content containing software authorization information; packaging the digital certificate into various services of the software system, and adding corresponding code logic include: Generate a key pair using an asymmetric encryption algorithm and save it in a private key library file, use the private key to digitally sign the content containing the authorization information and generate a digital certificate, package the public key and the generated digital certificate into each service of the software system, and add corresponding code logic; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node; When the service is started, executing the code logic to obtain the host information and the information of the digital certificate, and performing digital certificate verification includes: When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

2. The method according to claim 1, characterized in that: The deployment of services for different deployment environments includes: If the deployment environment is a virtual machine or cloud host, start it through the command line or script; If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service; If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

3. The method according to claim 2, characterized in that The method further comprises: After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

4. A software authorization system compatible with different deployment environments, characterized in that: The system comprises: A generation module, used to generate a digital certificate according to an asymmetric encryption algorithm and content containing software authorization information; package the digital certificate into various services of the software system, and add corresponding code logic; A deployment module is used to deploy services for different deployment environments, including virtual machines or cloud hosts, container environments, and container cloud platform environments; A verification module, used to execute the code logic to obtain the host information and the digital certificate information when the service is started, and perform digital certificate verification; The generation module generates a digital certificate according to an asymmetric encryption algorithm and the content containing software authorization information; packages the digital certificate into each service of the software system, and adds corresponding code logic including: Generate a key pair using an asymmetric encryption algorithm and save it in a private key library file, use the private key to digitally sign the content containing the authorization information and generate a digital certificate, package the public key and the generated digital certificate into each service of the software system, and add corresponding code logic; wherein the authorization information includes the validity period of the software license, the IP address list and MAC address list of the virtual machine and / or container host and / or container cloud platform node; When the service is started, the verification module executes the code logic to obtain the host information and the information of the digital certificate, and performs digital certificate verification including: When the service starts, the added code logic is executed, the digital certificate is loaded and verified with the public key, the software authorization information is obtained, the environment is determined based on the environment variables and the IP address and MAC address of the host machine are obtained, and the IP address and MAC address are compared with the content in the software authorization information. If the comparison is passed, the service is allowed to start, otherwise the service startup is terminated.

5. The system according to claim 4, characterized in that The deployment module performs service deployment for different deployment environments including: If the deployment environment is a virtual machine or cloud host, start it through the command line or script; If the deployment environment is a container environment, add environment variables DOCKER_NODE_IP and DOCKER_NODE_MAC to the startup script, which represent the IP address and MAC address of the host machine respectively, and use the script or deployment tool to start the docker image to run the service; If the deployment environment is a container cloud platform environment, add environment variables K8S_NODE_IP and K8S_NODE_MAC to the deployment script, which represent the IP address and MAC address of the k8s host node respectively, and use the deployment tool or deployment platform to create and schedule services.

6. The system according to claim 5, characterized in that The verification module is also used for: After the service is started, each user request is intercepted and verified to see if the current certificate is still valid. If the certificate is expired, the current request is terminated and an error message is returned.

Citation Information

Patent Citations

  • Deployment of containers based on environment requirements

    CN111279309A

  • Service arrangement method and system based on application environment

    CN111367534A