Application Management Method, Device, and Storage Medium
By performing two verifications on the application to be distributed in the application release system, combining the resource management of the design and operation states, the security and stability problems of K8S for cloud-native applications in resource allocation are solved, ensuring that the resource allocation complies with the design plan, and realizing non-invasive resource management.
Patent Information
- Application Number
- CN202211213250.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-09-30
AI Technical Summary
Kubernetes (K8S) lacks management of cloud-native application resources, which may compromise cluster security and stability, especially when users do not restrict them, the allocation of resources declared in Yaml may exceed actual requirements.
The application release system performs two verifications on the application to be distributed, the first verification is based on the configuration information based on the design state, and the second verification is based on the operating state resource state. Combined with multi-K8S cluster management, it ensures that the resource allocation complies with the design planning, and uses the native K8S protocol for container creation and startup.
It realizes effective management of cloud-native application resources, reduces security and stability threats to K8S clusters, and does not require invasive modification of application deployment scripts.
Smart Images

Figure CN115794133B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the cloud-native application technology of financial technology (Fintech), and particularly to an application management method, device, and storage medium. Background Art
[0002] With the development of computer technology, more and more technologies are applied in the financial field. The traditional financial industry is gradually transforming into financial technology, and container technology is no exception. However, due to the security and real-time requirements of the financial industry, higher requirements are put forward for container technology.
[0003] In related technologies, a container is the basic unit for resource allocation and scheduling of physical computing nodes. With the continuous development of container technology, new virtualization technologies provide an efficient operating environment for services and achieve the unification of virtual resources on different servers. Its basic principle is to divide the virtual resources corresponding to multiple servers into multiple application containers, enabling developers to package an application into a portable container and publish it to any computer to achieve containerization of the application. Currently, Kubernetes, abbreviated as K8S, is a popular container orchestration and management technology that can manage application containers on multiple servers in a cluster and achieve application deployment, planning, update, and maintenance. And providing cloud-native applications based on K8S is a technology that every cloud provider or cloud developer must master.
[0004] However, K8S lacks management of cloud-native application resources. For example, if a user declares a certain amount of resources in Yaml, K8S will allocate equivalent resources during actual operation. If the user's Yaml involves global resources such as K8S Service and Namespace, without restrictions, it may endanger the security and stability of the entire K8S cluster. Summary of the Invention
[0005] To solve the problems existing in the prior art, this application provides an application management method, device, and storage medium.
[0006] In a first aspect, an embodiment of this application provides an application management method. The method is applied to an application release system, and the method includes:
[0007] Obtain an application release request, and based on the application release request, obtain first configuration information of the application to be released from an application management system;
[0008] According to the application release request and the first configuration information, perform a first verification on the application to be released. If the first verification passes, release the workload of the application to be released to the K8S platform, so that the K8S platform creates containers according to the workload of the application to be released and triggers a creation callback to the application release system, where the K8S platform includes multiple K8S clusters;
[0009] According to the creation callback, obtain the second configuration information of the application to be released from the application management system and add the second configuration information to the container;
[0010] Obtain the resource status of the multiple K8S clusters from the application management system, and perform a second verification on the application to be released according to the resource status of the multiple K8S clusters. If the second verification passes, send a container creation success message to the K8S platform, so that the K8S platform starts the container based on the container creation success message.
[0011] In a possible implementation, the application release request carries the identifier of the application to be released;
[0012] The obtaining of the first configuration information of the application to be released from the application management system based on the application release request includes:
[0013] Based on the identifier of the application to be released, obtain the first configuration information of the application to be released from the application management system.
[0014] In a possible implementation, the application release request further carries the release package of the application to be released, and the first configuration information includes the namespace, workload, and total computing resources used by the application to be released;
[0015] The performing of the first verification on the application to be released according to the application release request and the first configuration information includes:
[0016] Verify the legality of the identifier of the application to be released;
[0017] If the identifier of the application to be released is verified to be legal, parse the release package of the application to be released to obtain the namespace, workload, and total computing resources declared by the application to be released;
[0018] Respectively verify whether the namespace, workload, and total computing resources declared by the application to be released are consistent with the namespace, workload, and total computing resources used by the application to be released.
[0019] In a possible implementation, the resource status of the multiple K8S clusters includes the applied computing resources of the multiple K8S clusters grouped by application. The applied computing resources include the type of resource object applied, the number of containers generated, and the total computing resources of the generated containers.
[0020] The second verification of the to-be-released application according to the resource status of the multiple K8S clusters includes:
[0021] Determine the type of resource object applied by the to-be-released application, the number of containers generated, and the total computing resources of the generated containers according to the resource status of the multiple K8S clusters.
[0022] Verify whether the type of resource object requested by the to-be-released application exceeds the type of resource object applied by the to-be-released application, whether the number of containers generated by the to-be-released application request exceeds the number of containers generated by the to-be-released application application, and verify whether the total computing resources of the containers generated by the to-be-released application request exceed the total computing resources of the containers generated by the to-be-released application application.
[0023] In a possible implementation, sending the container creation success information to the K8S platform so that the K8S platform starts the container based on the container creation success information includes:
[0024] Send the container creation success information to the K8S platform so that the K8S platform performs container node scheduling in the application management system based on the container creation success information to obtain the correspondence between container nodes - physical machines - racks - data centers, and based on the correspondence, the first policy and the second policy, determine the target container node and start the container.
[0025] In a possible implementation, the first policy includes preselection for high availability of racks, preselection for high availability of data centers, preselection for high availability of K8S clusters, preselection for resource reservation of nodes, and preselection for container resources. Among them, the preselection for high availability of racks is used to preselect that the container nodes of a module in the application cluster are deployed on at least two racks, the preselection for high availability of data centers is used to preselect that the container nodes of a module in the application cluster are deployed on at least two data centers, the preselection for high availability of K8S clusters is used to preselect that the container nodes of a module in the application cluster are deployed on at least two K8S clusters, the preselection for resource reservation of nodes is used to preselect that the container nodes reserve a preset percentage of resources, and the preselection for container resources is used to preselect that the resources of the container nodes meet the preset requirements.
[0026] In a possible implementation, the second policy includes a container node load scoring policy, a service affinity scoring policy, and a host-level high availability scoring policy for workloads. Among them, the container node load scoring policy scores based on the real-time resource utilization of container nodes, the service affinity scoring policy scores based on the affinity between container nodes on the same data center, and the host-level high availability scoring policy for workloads scores based on the situation of container nodes under the same workload on the host.
[0027] In a possible implementation, the second configuration information includes the environment variables of the application, Role-Based Access Control (RBAC) permissions, and preset configurations for scheduling.
[0028] In a second aspect, an application management device provided by an embodiment of the present application is applied to an application release system. The device includes:
[0029] An acquisition module, configured to acquire an application release request, and based on the application release request, acquire first configuration information of the application to be released from an application management system;
[0030] A first verification module, configured to perform a first verification on the application to be released according to the application release request and the first configuration information. If the first verification passes, the workload of the application to be released is published to the K8S platform, so that the K8S platform creates containers according to the workload of the application to be released and triggers a creation callback to the application release system, where the K8S platform includes multiple K8S clusters;
[0031] An addition module, configured to acquire second configuration information of the application to be released from the application management system according to the creation callback, and add the second configuration information to the container;
[0032] A second verification module, configured to acquire the resource status of the multiple K8S clusters from the application management system, and perform a second verification on the application to be released according to the resource status of the multiple K8S clusters. If the second verification passes, a container creation success message is sent to the K8S platform, so that the K8S platform starts the container based on the container creation success message.
[0033] In a possible implementation, the application release request carries the identifier of the application to be released;
[0034] The acquisition module is specifically configured to:
[0035] Based on the identifier of the application to be released, acquire first configuration information of the application to be released from the application management system.
[0036] In a possible implementation, the application release request further carries the release package of the application to be released, and the first configuration information includes the namespace, workload, and total computing resources used by the application to be released;
[0037] The first verification module is specifically configured to:
[0038] Verify the legality of the identifier of the application to be released;
[0039] If the identifier of the application to be released is verified to be legal, then parse the release package of the application to be released to obtain the namespace, workload, and total computing resources declared to be used by the application to be released;
[0040] Respectively verify whether the namespace, workload, and total computing resources declared to be used by the application to be released are consistent with the namespace, workload, and total computing resources used by the application to be released.
[0041] In a possible implementation, the resource status of the multiple K8S clusters includes the applied computing resources grouped by application for the multiple K8S clusters, and the applied computing resources include the type of resource object applied for, the number of containers generated, and the total computing resources of the generated containers;
[0042] The second verification module is specifically configured to:
[0043] Based on the resource status of the multiple K8S clusters, determine the type of resource object applied for by the application to be released, the number of containers generated, and the total computing resources of the generated containers;
[0044] Verify whether the type of resource object requested by the application to be released exceeds the type of resource object applied for by the application to be released, whether the number of containers requested to be generated by the application to be released exceeds the number of containers applied to be generated by the application to be released, and verify whether the total computing resources of the containers requested to be generated by the application to be released exceed the total computing resources of the containers applied to be generated by the application to be released.
[0045] In a possible implementation, the second verification module is specifically configured to:
[0046] Send a container creation success message to the K8S platform, so that the K8S platform, based on the container creation success message, implements container node scheduling in the application management system to obtain the correspondence between container nodes - physical machines - racks - data centers, and based on the correspondence, the first policy, and the second policy, determine the target container node and start the container.
[0047] In a possible implementation, the first policy includes preselection for rack high availability, preselection for data center high availability, preselection for K8S cluster high availability, preselection for node resource reservation, and preselection for container resources. Among them, the preselection for rack high availability is used to preselect that the container nodes of a module in the application cluster are deployed on at least two racks; the preselection for data center high availability is used to preselect that the container nodes of a module in the application cluster are deployed on at least two data centers; the preselection for K8S cluster high availability is used to preselect that the container nodes of a module in the application cluster are deployed on at least two K8S clusters; the preselection for node resource reservation is used to preselect that the container nodes reserve a preset percentage of resources; and the preselection for container resources is used to preselect that the resources of the container nodes meet the preset requirements.
[0048] In a possible implementation, the second policy includes a container node load scoring policy, a service affinity scoring policy, and a host-level high availability scoring policy for the workload. Among them, the container node load scoring policy scores based on the real-time resource utilization of the container nodes; the service affinity scoring policy scores based on the affinity between the container nodes on the same data center; and the host-level high availability scoring policy for the workload scores based on the location of the container nodes on the host under the same workload.
[0049] In a possible implementation, the second configuration information includes the environment variables of the application, RBAC permissions, and preset configurations for scheduling.
[0050] In a third aspect, an embodiment of the present application provides an application publishing system, including:
[0051] A processor;
[0052] A memory; and
[0053] A computer program;
[0054] Wherein, the computer program is stored in the memory and is configured to be executed by the processor, and the computer program includes instructions for executing the method described in the first aspect.
[0055] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program, and the computer program enables the server to execute the method described in the first aspect.
[0056] In a fifth aspect, an embodiment of the present application provides a computer program product, including computer instructions, and the computer instructions are executed by the processor to execute the method described in the first aspect.
[0057] The application management method, device, and storage medium provided by the embodiments of this application. The method obtains an application release request through an application release system, and based on this request, obtains the first configuration information of the application to be released from an application management system. Furthermore, according to the above request and the first configuration information, the application to be released is subjected to a first verification. If the verification passes, the workload of the application to be released is published to the K8S platform, so that the K8S platform creates containers and triggers a creation callback to the application release system. Among them, the K8S platform includes multiple K8S clusters. Therefore, according to the above creation callback, the application release system obtains the second configuration information of the application to be released from the application management system and adds this information to the above containers, obtains the resource status of multiple K8S clusters from the application management system, and according to this resource status, the application to be released is subjected to a second verification. If the verification passes, a container creation success message is sent to the K8S platform, so that the K8S platform starts the containers based on this information. Among them, the embodiments of this application can perform resource management and verification on cloud-native applications, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster. Moreover, the embodiments of this application can use the native K8S protocol without any intrusion into the application deployment script. Brief Description of the Drawings
[0058] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0059] Figure 1 It is a schematic diagram of an application management system architecture provided by the embodiments of this application;
[0060] Figure 2 It is a schematic flowchart of an application management method provided by the embodiments of this application;
[0061] Figure 3 It is a schematic diagram of an application management system provided by the embodiments of this application for monitoring and storing real-time resources of an application;
[0062] Figure 4 It is a schematic flowchart of another application management method provided by the embodiments of this application;
[0063] Figure 5 It is a schematic diagram of the first strategy and the second strategy provided by the embodiments of this application;
[0064] Figure 6 It is a schematic diagram of the relationship between a cluster, a module, and a container provided by the embodiments of this application;
[0065] Figure 7 A schematic diagram for implementing container node scheduling in an application management system provided by an embodiment of the present application;
[0066] Figure 8 A flowchart of yet another application management method provided by an embodiment of the present application;
[0067] Figure 9 A schematic diagram of the structure of an application management device provided by an embodiment of the present application;
[0068] Figure 10 Shows a possible schematic diagram of the application release system of the present application. Detailed implementation manners
[0069] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0070] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0071] Currently, in the cloud-native practice of the financial industry, considering the overall cost and the scale of the data center, resources cannot be infinitely allocated. Therefore, it is necessary to strictly allocate and manage resources. K8S provides the scheduling and orchestration capabilities of containers, but lacks the management of application resources. For example, if a user declares a certain amount of resources in Yaml, K8S will allocate equal resources during actual operation. If the user's Yaml involves global resources such as K8S Service and Namespace, without restrictions, it may endanger the security and stability of the entire K8S cluster.
[0072] To solve the above problems, an application management method is proposed in an embodiment of the present application, which manages resources in the design state, performs statistics and verification on resources in the running state, and supports joint management of multiple K8S clusters. Exemplarily, in this embodiment, the application publishing system performs the first statistics on resources in the running state, manages resources based on this statistics and the design state, and performs the first verification. If the verification passes, a creation callback is triggered through multiple K8S clusters. As a result, the application publishing system performs the second statistics on resources in the running state, manages resources based on this statistics and the design state, and performs the second verification. If the verification passes, container startup is performed through multiple K8S clusters, realizing the management and verification of cloud native application resources, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster, and moreover, the native K8S protocol can be used without any intrusion into the application deployment script.
[0073] Among them, the design state: the link of design and planning according to enterprise planning, platform specifications, and application requirements, before the running state, to prevent applications from using resources unrestrictedly during operation. For example, if there are 1000 central processing unit (CPU) cores available in the current platform resource pool, when multiple applications go online, it is necessary to coordinate resources during deployment design. For example, application A applies to use 300 cores, and finally it is not allowed to exceed this value. Otherwise, it will affect the deployment of other applications.
[0074] The running state: after the application is deployed through the application publishing system, the container is truly started as the running state (runtime).
[0075] Optionally, an application management method provided by the present application can be applicable to Figure 1 the schematic diagram of the application management system architecture shown, as Figure 1 shown, the system may include an application publishing system, an application management system, and a K8S platform, and the K8S platform includes multiple K8S clusters. Here, Figure 1 K8S cluster 1 and K8S cluster 2 are taken as examples for the K8S platform.
[0076] In the specific implementation process, in the design state, relevant personnel, such as users, can apply for resources from the application management system. The application management system verifies the application access rights of the above personnel, allocates an initial K8S cluster, and creates an identifier for the application, such as an application ID (APP ID). After the application is successful, the application management system can return the application ID to the above personnel for subsequent use of the application.
[0077] In the running state, the application management system can obtain all the above K8S clusters, namely K8S Cluster 1 and K8S Cluster 2, and calculate the resources grouped by application ID. Further, the application management system can also write the resources into the cache module, store them in the container platform resource management system, and then synchronize the information to the Configuration Management Database (CMDB), etc. When an application is released, relevant personnel initiate an application release to the application release system. The application release system conducts the first statistics on the resources, manages the resources based on this statistics and the design state, and conducts the first verification. If the verification passes, it triggers the creation of a callback through the K8S platform. Furthermore, the application release system calculates the resources grouped by the above application ID, conducts the second statistics on the resources, manages the resources based on this statistics and the design state, and conducts the second verification. If the verification passes, it starts the container through the K8S platform to achieve the management and verification of cloud-native application resources, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster.
[0078] Among them, the above relevant personnel can interact with the application release system and the application management system through the Application Programming Interface (API) gateway. The K8S platform can trigger the creation of a callback through the event callback system.
[0079] It should be understood that the above system is only an exemplary system, and in specific implementation, it can be set according to application requirements.
[0080] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the architecture of the application management system. In other feasible embodiments of the present application, the above architecture may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or have different component arrangements, which can be specifically determined according to the actual application scenario and are not limited herein. Figure 1 The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0081] In addition, the system architecture described in the embodiments of the present application is to more clearly illustrate the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.
[0082] Next, several embodiments are used as examples to describe the technical solutions of the present application. For the same or similar concepts or processes, they may not be repeated in some embodiments.
[0083] Figure 2The flowchart of an application management method provided by an embodiment of this application. The execution subject of this embodiment can be Figure 1 the application release system in the embodiment shown, which can be determined according to the actual situation. For example Figure 2 As shown, the application management method provided by the embodiment of this application includes the following steps:
[0084] S201: Obtain an application release request. Based on this application release request, obtain the first configuration information of the application to be released from the application management system.
[0085] Among them, the above application release request carries the identifier of the above application to be released, such as the application ID. Here, the identifier of the above application to be released can be in the design state. Relevant personnel apply for application resources from the application management system. The application management system verifies the application access rights of the above personnel, allocates an initial K8S cluster, and creates a unique identifier of the application for subsequent use of the application.
[0086] Optionally, when this embodiment obtains the first configuration information of the application to be released from the application management system based on the above application release request, it can obtain the first configuration information of the application to be released from the application management system based on the identifier of the above application to be released. Among them, the first configuration information can include the namespace, workload, and total computing resources used by the above application to be released, etc.
[0087] S202: Perform a first verification on the above application to be released according to the above application release request and the first configuration information. If the first verification passes, release the workload of the above application to be released to the K8S platform, so that the K8S platform creates containers according to the workload of the above application to be released, and triggers a creation callback to the application release system, where the above K8S platform includes multiple K8S clusters.
[0088] Here, the above application release request can also carry the release package of the above application to be released. When this embodiment performs a first verification on the above application to be released according to the above application release request and the first configuration information, it can verify the legality of the identifier of the above application to be released. If the identifier of the above application to be released is verified to be legal, then parse the release package of the above application to be released to obtain the namespace, workload, and total computing resources declared by the above application to be released to be used. Thus, respectively verify whether the namespace, workload, and total computing resources declared by the above application to be released to be used are consistent with the namespace, workload, and total computing resources used by the above application to be released.
[0089] If the namespaces, workloads, and total computing resources to be used in the above-mentioned application release declaration are consistent with those used in the above-mentioned application to be released, that is, the namespace to be used in the above-mentioned application release declaration is consistent with the namespace used in the above-mentioned application to be released, the workload to be used in the above-mentioned application release declaration is consistent with the workload used in the above-mentioned application to be released, and the total computing resources to be used in the above-mentioned application release declaration are consistent with the total computing resources used in the above-mentioned application to be released, then this embodiment can determine that the first verification passes, and release the workload of the above-mentioned application to be released to the K8S platform. Otherwise, it is determined that the first verification fails, the operation is stopped, and a prompt for the failure of the first verification can be given so that relevant personnel can view and process it in a timely manner.
[0090] In this embodiment, resource management and verification can be performed on cloud-native applications during application release, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster.
[0091] In addition, after the K8S platform receives the workload (native k8s protocol) of the above-mentioned application to be released from the application release system, it can create containers according to the workload of the above-mentioned application to be released. For example, set the webhook hook function for container creation, and create containers through this hook function and the workload of the above-mentioned application to be released, and trigger a creation callback to the application release system. Among them, the workload of the above-mentioned application to be released can include workload types such as "DaemonSet", "StatefulSet", "Deployment", "ReplicaSet", "Job", "CronJob". Therefore, the K8S platform can create containers according to the above-mentioned hook function and the above-mentioned workload type, improving the accuracy of container creation.
[0092] Here, this embodiment can use the native K8S protocol without any intrusion into the application deployment script.
[0093] S203: According to the above-mentioned creation callback, obtain the second configuration information of the above-mentioned application to be released from the above-mentioned application management system, and add the second configuration information to the above-mentioned container.
[0094] Exemplarily, in this embodiment, the callback can be created according to the above, and based on the identifier of the application to be released, the second configuration information of the application to be released can be obtained from the above application management system. Among them, the second configuration information can include the environment variables of the application (such as database address, system configuration, etc.), RBAC permissions (such as the permissions required for the application to access K8S), and preset configurations for scheduling (requirements for container nodes, such as the need for a graphics processing unit (GPU) node; requirements for the data center; tolerance for network latency, etc.).
[0095] Here, the container objects in K8S do not have the second configuration information of the application to be released. In order to ensure the operation verification and monitoring of the cluster, it is necessary to inject the above information into the container, so that all container objects add the label: app-cluster:cluster-instance-id, where cluster-instance-id is the identifier of the application to be released, such as the application ID. Among them, it is not necessary to put the above information into the K8S yaml file, so as to maintain non-invasiveness to the K8S workload.
[0096] S204: Obtain the resource status of the above multiple K8S clusters from the above application management system, and perform a second verification on the application to be released according to the resource status of the above multiple K8S clusters. If the second verification passes, send a container creation success message to the above K8S platform, so that the above K8S platform can start the container based on the container creation success message.
[0097] Among them, the application management system can obtain the resources calculated by grouping the above multiple K8S clusters by application ID in the running state. Further, the resources can be written into the cache module and stored in the container platform resource management system, and then the information can be synchronized to CMDB, etc.
[0098] Here, the application management system stores the resources calculated by grouping the above multiple K8S clusters by application ID at one time, so that the resource status of all K8S clusters can be directly determined from the stored information later, without having to traverse all K8S clusters, realizing millisecond-level resource statistics.
[0099] Exemplarily, when the application management system obtains and stores the resources calculated by grouping the above multiple K8S clusters by application ID in the running state, the cluster ID + type (CPU, memory, disk, number of containers, CustomResource Definition (CRD)) can be used as the Key, and the value can be used as the Value for storage. For example: the configuration of cluster cls110:
[0100] Cls-110-cpu = 100: The number of CPUs used in Cluster 110 is 100.
[0101] Cls-110-memory = 200: The memory usage of Cluster 110 is 200G.
[0102] Cls-110-pods = 50: The number of containers in Cluster 110 is 50.
[0103] In addition, as Figure 3 shown, taking the above-mentioned multiple K8S clusters including K8S Cluster 1, K8S Cluster 2, and K8S Cluster N as examples, when the application management system is in the running state and obtains the resources calculated by grouping the above-mentioned multiple K8S clusters by application ID for storage, in addition to writing the resources into the cache module (distributed cache module) and storing them in the container platform resource management system, and then synchronizing the information to CMDB, it can also provide query services externally through the interface of the container platform resource management system. Among them, the K8S resource monitor can also be used here to manage the resources of all K8S clusters, and then the application management system can obtain the resources calculated by grouping all K8S clusters by application ID from the K8S resource monitor through the informer mechanism.
[0104] Optionally, in this embodiment, after creating the callback according to the above, obtaining the second configuration information of the to-be-released application from the above application management system, and adding the second configuration information to the above container, the resource status of the above multiple K8S clusters can be directly obtained from the application management system, without having to traverse all K8S clusters, achieving millisecond-level resource statistics. Then, according to the resource status of the above multiple K8S clusters, the to-be-released application is secondarily verified. After the verification passes, a container creation success message is sent to the K8S platform to start the container.
[0105] Among them, the resource status of the above multiple K8S clusters may include the application-calculated requested resources of the multiple K8S clusters grouped by application. The requested calculated resources include the type of resource object requested, the number of containers generated, and the total calculated resources of the generated containers, etc. In this embodiment, when secondarily verifying the to-be-released application according to the resource status of the above multiple K8S clusters, the type of resource object requested by the to-be-released application, the number of containers generated, and the total calculated resources of the generated containers can be determined according to the resource status of the above multiple K8S clusters. Furthermore, it is verified whether the type of resource object requested by the to-be-released application exceeds the type of resource object requested by the to-be-released application, whether the number of containers generated by the to-be-released application request exceeds the number of containers generated by the to-be-released application request, and whether the total calculated resources of the containers generated by the to-be-released application request exceed the total calculated resources of the containers generated by the to-be-released application request.
[0106] If the resource object type of the to-be-released application request is verified and does not exceed the resource object type of the to-be-released application application, the number of containers generated by the to-be-released application request does not exceed the number of containers generated by the to-be-released application application, and the total computing resources of the containers generated by the to-be-released application request are verified and do not exceed the total computing resources of the containers generated by the to-be-released application application, then this embodiment determines that the second verification passes, and sends a container creation success message to the K8S platform to start the container. Otherwise, it is determined that the second verification fails, and a container creation failure message is sent to the K8S platform to stop the operation. For example, when verifying the resource object type of the to-be-released application request, it exceeds the resource object type of the to-be-released application application: if creating a CRD is not supported during application, but the application request creates a new CRD, the request is rejected and the container creation fails; another example is that the number of containers generated by the to-be-released application request exceeds the number of containers generated by the to-be-released application application: if a maximum of 10 containers are applied for, and the 11th container is created in the application request, the request is rejected and the container creation fails; the total computing resources of the containers generated by the to-be-released application request exceed the total computing resources of the containers generated by the to-be-released application application: if the total CPU resource applied for is 9 cores, and if an 11-core CPU resource total is required in the application request, the request is rejected and the container creation fails.
[0107] Here, when the application is released, this embodiment can perform resource management and verification on cloud-native applications, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster.
[0108] In the embodiment of the present application, an application release request is obtained through an application release system. Based on this request, the first configuration information of the to-be-released application is obtained from the application management system. Furthermore, according to the above request and the first configuration information, the to-be-released application is subjected to the first verification. If the verification passes, the workload of the to-be-released application is released to the K8S platform, so that the K8S platform creates a container and triggers a creation callback to the application release system. Among them, the K8S platform includes multiple K8S clusters. Therefore, the application release system obtains the second configuration information of the to-be-released application from the application management system according to the above creation callback, adds this information to the above container, obtains the resource status of multiple K8S clusters from the application management system, and according to this resource status, performs a second verification on the to-be-released application. If the verification passes, a container creation success message is sent to the K8S platform, so that the K8S platform starts the container based on this information. Among them, the embodiment of the present application can perform resource management and verification on cloud-native applications, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster. Moreover, the embodiment of the present application can use the native K8S protocol without any intrusion into the application deployment script.
[0109] In addition, in this embodiment, the resource status of the multiple K8S clusters is obtained from the above application management system, and the to-be-released application is secondarily verified according to the resource status of the multiple K8S clusters. If the secondary verification passes, a container creation success message is sent to the above K8S platform, so that the K8S platform, based on the container creation success message, performs container node scheduling in the application management system to obtain the correspondence between container nodes, physical machines, racks, and data centers, and determines target container nodes based on this correspondence, the first policy, and the second policy, and starts the containers. Here, the first policy and the second policy can be customized according to the actual situation, that is, this embodiment supports the implementation of customized first and second policies to solve the problem that the existing resource management policies for cloud-native applications are too single and do not meet the actual requirements. As Figure 4 shown, another application management method is provided, including:
[0110] S401: Obtain an application release request, and based on the application release request, obtain the first configuration information of the to-be-released application from the application management system.
[0111] S402: According to the application release request and the first configuration information, perform a primary verification on the to-be-released application. If the primary verification passes, publish the workload of the to-be-released application to the K8S platform, so that the K8S platform creates containers according to the workload of the to-be-released application and triggers a creation callback to the application release system, where the above K8S platform includes multiple K8S clusters.
[0112] S403: According to the above creation callback, obtain the second configuration information of the to-be-released application from the application management system and add the second configuration information to the above container.
[0113] Among them, steps S401 - S403 are as described above Figure 2 and will not be elaborated here.
[0114] S404: Obtain the resource status of the multiple K8S clusters from the application management system, and according to the resource status of the multiple K8S clusters, perform a secondary verification on the to-be-released application. If the secondary verification passes, send a container creation success message to the above K8S platform, so that the K8S platform, based on the container creation success message, performs container node scheduling in the application management system to obtain the correspondence between container nodes, physical machines, racks, and data centers, and determines target container nodes based on this correspondence, the first policy, and the second policy, and starts the containers.
[0115] Here, as Figure 5As shown, the above first strategy may include preselection for high availability of racks, preselection for high availability of data centers, preselection for high availability of K8S clusters, preselection for reserved node resources, and preselection for container resources, etc.
[0116] Among them, the above preselection for high availability of racks is used to preselect that the container nodes of a module in the application cluster are deployed on at least two racks. Here, the containers of a module should be dispersed on as many racks as possible, and the number of all instances of a module on one rack is forced to <= 50% (the rack is a physical rack, and physical problems such as power failure and switch failure may occur, affecting the use of servers on the entire rack. Therefore, the container allocation of the module is scattered by rack to solve the above problems).
[0117] The above preselection for high availability of data centers is used to preselect that the container nodes of a module in the application cluster are deployed on at least two data centers, that is, the containers of a module are deployed on two or more data centers to avoid service unavailability caused by single data center failure.
[0118] The above preselection for high availability of K8S clusters is used to preselect that the container nodes of a module in the application cluster are deployed on at least two K8S clusters, that is, the containers of a module are deployed on two or more K8S clusters to reduce service unavailability caused by single K8S cluster failure.
[0119] The above preselection for reserved node resources is used to preselect that the container nodes reserve a preset percentage of resources. For example, each node reserves a part of the CPU and memory for the Operating System (OS) and system processes to use, such as setting the percentage of reserved resources to 10%.
[0120] The above preselection for container resources is used to preselect that the resources of the container nodes meet the preset requirements. For example, if a container requires 4G of memory, nodes that do not meet 4G will be excluded. Or, some containers require Solid State Disk (SSD) or Solid State Drive (SSD), and some require GPU, and node selection is performed according to their requirements.
[0121] It should be noted here that a cluster is the sum of resources, a module is the smallest architectural unit in the cluster, realizing an independent function, such as providing a query interface, providing a reconciliation function, etc. A container is the smallest running unit, and a module contains multiple containers. Exemplarily, the relationship between a cloud-native application cluster, a cloud-native application module, and a container can be as Figure 6 shown. Cluster A1 corresponds to Module B and Module C, Cluster A2 corresponds to Module B and Module C. Module B includes container pod1, container pod2, and container pod3, and Module C includes container pod4... container podN.
[0122] Optionally, asFigure 5 As shown, the above second strategy may include a container node load scoring strategy, a service affinity scoring strategy, and a host-level high availability scoring strategy for workloads.
[0123] Among them, the above container node load scoring strategy scores based on the real-time resource utilization of the container node. For example, if the real-time resource utilization rate of the container node is high, the score of this container node load is also high; if the real-time resource utilization rate of the container node is low, the score of this container node load is also low.
[0124] The above service affinity scoring strategy scores based on the affinity between container nodes on the same data center. Here, there are some mutual call relationships between some services, that is, there is affinity. If these applications are deployed on the same data center, it is beneficial to reduce the call latency of the network. Therefore, it scores based on the affinity between container nodes on the same data center. High affinity indicates that applications with mutual call relationships are deployed on the same data center, and the score is also high; low affinity indicates that applications without mutual call relationships are deployed on the same data center, and the score is also low.
[0125] The above host-level high availability scoring strategy for workloads scores based on the situation of container nodes of the same workload on the host. Among them, although the ones selected by the above first strategy meet rules such as rack high availability, there is still a possibility that the same module may be too concentrated. Therefore, it is necessary to scatter them here. Multiple container instances of the same workload are homogeneous and jointly provide services externally. As long as one instance can work normally, the service will not be unavailable. The above host-level high availability scoring strategy for workloads means to scatter these same instances as much as possible at the host level. When container nodes of the same workload are on the same host, the score is relatively low; when container nodes of the same workload are on different hosts, the score is relatively high, so as to avoid service unavailability caused by a single host failure.
[0126] Furthermore, the above container node load scoring strategy, service affinity scoring strategy, and host-level high availability scoring strategy for workloads correspond to different weights respectively. After scoring, they are multiplied by the corresponding weights respectively, and finally, the total score is obtained based on the obtained products.
[0127] In this embodiment, taking 2,000 nodes shared by all clusters as an example, 100 nodes are selected through the above-mentioned pre-selection of rack high availability, pre-selection of data center high availability, pre-selection of K8S cluster high availability, pre-selection of node resource reservation, and pre-selection of container resources. The 100 nodes are scored according to the container node load scoring strategy. The higher the score of this item, the more ideal the node, and the score of this item is S1. The 100 nodes are scored according to the business affinity scoring strategy. The higher the score of this item, the more ideal the node under the data center, and the score of this item is S2. The 100 nodes are scored according to the host-level high availability scoring strategy of the workload. The higher the score of this item, the less ideal the node, and the score of this item is S3. Composite calculation is performed according to the weights corresponding to the above-mentioned container node load scoring strategy, business affinity scoring strategy, and host-level high availability scoring strategy of the workload. For example, the weight of the container node load scoring strategy is 30%, the weight of the business affinity scoring strategy is 20%, and the weight of the host-level high availability scoring strategy of the workload is 50%. Finally, the total score is obtained to select the node with the higher total score for scheduling later.
[0128] In addition, the specific strategies included in the above first strategy and second strategy can be adjusted according to actual situations to meet various application requirements.
[0129] In a possible implementation manner, this embodiment sends a container creation success message to the above K8S platform, so that the K8S platform, based on the container creation success message, implements container node scheduling in the above application management system, such as Figure 7 shown, obtain the schedule query scheduling command from the container platform cluster master node, obtain the real-time load of the nodes through the prometheus aggregation query service in the container platform cloud native application management service, obtain the infrastructure as a service (IaaS) resources in the container platform resource management system, and synchronize the relationship between the container node - physical machine - rack - data center from the CMDB, so as to determine the target container node and start the container based on the corresponding relationship, the first strategy, and the second strategy later.
[0130] In the embodiment of the present application, a container creation success message is sent to the above K8S platform, so that the K8S platform, based on the container creation success message, implements container node scheduling in the above application management system to obtain the corresponding relationship between the container node - physical machine - rack - data center, and based on the corresponding relationship, the first strategy, and the second strategy, determine the target container node and start the container. Among them, the first strategy and the second strategy can be customized according to actual situations, that is, this embodiment supports the implementation of customized first strategy and second strategy to solve the problem that the existing resource management strategy for cloud native applications is too single and does not meet the actual requirements.
[0131] Here, Figure 8Schematic flowchart of another application management method proposed in the embodiments of the present application. As Figure 8 shown, in this embodiment, multi-terminal interaction is carried out among relevant personnel, application release system, application management system, and K8S platform to manage cloud-native applications. Among them, the K8S platform includes multiple K8Ss. The method includes:
[0132] 1.1: In the design state, relevant personnel can apply for resources from the application management system.
[0133] 1.2: The application management system verifies the application access rights of the above personnel, allocates an initial K8S cluster, and creates an identifier of the application, such as an application ID.
[0134] 1.3: When the application is successfully applied, the application management system can return the application ID to the above personnel for subsequent use of the application.
[0135] 2.1: In the running state, the application management system can monitor the running status of each K8S resource, that is, obtain all the above K8S clusters and calculate the resources grouped by the application ID.
[0136] 2.2: The application management system stores the implementation resources, that is, writes the above resources into the cache module and stores them in the container platform resource management system, and then synchronizes the information to CMDB, etc.
[0137] 3.1: When the application is released, relevant personnel initiate an application release request to the application release system.
[0138] 3.2: Based on the above application release request, the application release system queries information from the application management system.
[0139] 3.3: The application management system returns the corresponding application cluster information of the application to be released to the application release system, that is, the first configuration information.
[0140] 3.4: The application release system performs a first verification (also called preliminary verification) on the application to be released according to the above application release request and the first configuration information.
[0141] 3.5: If the first verification passes, the application release system releases the workload of the application to be released to the K8S platform.
[0142] 4.1: The K8S platform creates a container and triggers a creation callback to the application release system.
[0143] 4.2: The application release system obtains the second configuration information of the application to be released from the application management system.
[0144] 4.3: The application release system modifies the definition and adds the second configuration information to the above container.
[0145] 4.4: The application release system obtains the real-time resource status from the application management system, that is, obtains the resource status of the above-mentioned multiple K8S clusters.
[0146] 4.5: The application release system performs a second verification on the to-be-released application according to the resource status of the above-mentioned multiple K8S clusters, that is, performs resource determination.
[0147] 4.6: If the second verification passes, the application release system sends a container creation success message to the K8S platform; otherwise, it sends a container creation failure message to the K8S platform.
[0148] 5.1: If it is a container creation success message, the K8S platform performs container node scheduling in the application management system to obtain the corresponding relationship between container nodes - physical machines - racks - data centers.
[0149] 5.2: The application management system determines the target container node based on the above corresponding relationship, the first policy, and the second policy.
[0150] 5.3: The K8S platform starts the container based on the target container node.
[0151] Compared with the prior art, the embodiments of the present application can perform resource management and verification on cloud-native applications, reducing the occurrence of situations that endanger the security and stability of the entire K8S cluster. Moreover, the embodiments of the present application can use the native K8S protocol without any intrusion into the application deployment script. In addition, the above first policy and second policy can be customized according to the actual situation, that is, the embodiments of the present application support the implementation of customized first and second policies, solving the problem that the existing resource management strategies for cloud-native applications are too single and do not meet the actual needs.
[0152] Corresponding to the application management method in the above embodiments, Figure 9 This is a schematic structural diagram of an application management device provided by the embodiments of the present application. For the sake of convenience of description, only the parts related to the embodiments of the present application are shown. Figure 9 This is a schematic structural diagram of an application management device provided by the embodiments of the present application. The application management device 90 includes: an acquisition module 901, a first verification module 902, an addition module 903, and a second verification module 904. It should be noted here that the division of the acquisition module, the first verification module, the addition module, and the second verification module is only a logical function division, and physically the two can be integrated or independent.
[0153] Among them, the acquisition module 901 is used to obtain an application release request, and based on the application release request, obtain the first configuration information of the to-be-released application from the application management system.
[0154] The first verification module 902 is configured to perform a first verification on the application to be released according to the application release request and the first configuration information. If the first verification passes, it releases the workload of the application to be released to the K8S platform, so that the K8S platform creates containers according to the workload of the application to be released and triggers a creation callback to the application release system, where the K8S platform includes multiple K8S clusters.
[0155] The addition module 903 is configured to obtain the second configuration information of the application to be released from the application management system according to the creation callback and add the second configuration information to the container.
[0156] The second verification module 904 is configured to obtain the resource status of the multiple K8S clusters from the application management system and perform a second verification on the application to be released according to the resource status of the multiple K8S clusters. If the second verification passes, it sends a container creation success message to the K8S platform, so that the K8S platform starts the container based on the container creation success message.
[0157] In a possible design, the application release request carries the identifier of the application to be released;
[0158] The obtaining module 901 is specifically configured to:
[0159] Based on the identifier of the application to be released, obtain the first configuration information of the application to be released from the application management system.
[0160] In a possible implementation manner, the application release request further carries the release package of the application to be released, and the first configuration information includes the namespace, workload, and total computing resources used by the application to be released;
[0161] The first verification module 902 is specifically configured to:
[0162] Verify the legality of the identifier of the application to be released;
[0163] If the identifier of the application to be released is verified to be legal, parse the release package of the application to be released to obtain the namespace, workload, and total computing resources declared by the application to be released;
[0164] Respectively verify whether the namespace, workload, and total computing resources declared by the application to be released are consistent with the namespace, workload, and total computing resources used by the application to be released.
[0165] In a possible implementation, the resource status of the multiple K8S clusters includes the applied computing resources of the multiple K8S clusters grouped by application. The applied computing resources include the type of resource object applied for, the number of containers generated, and the total computing resources of the generated containers.
[0166] The second verification module 904 is specifically configured to:
[0167] Determine the type of resource object applied for by the application to be released, the number of containers generated, and the total computing resources of the generated containers according to the resource status of the multiple K8S clusters;
[0168] Verify whether the type of resource object requested by the application to be released exceeds the type of resource object applied for by the application to be released, whether the number of containers generated by the application request to be released exceeds the number of containers generated by the application to be released, and verify whether the total computing resources of the containers generated by the application request to be released exceed the total computing resources of the containers generated by the application to be released.
[0169] In a possible implementation, the second verification module 904 is specifically configured to:
[0170] Send a container creation success message to the K8S platform, so that the K8S platform, based on the container creation success message, implements container node scheduling in the application management system to obtain the correspondence between container nodes - physical machines - racks - data centers, and based on the correspondence, the first policy, and the second policy, determine the target container node and start the container.
[0171] In a possible implementation, the first policy includes rack high-availability preselection, data center high-availability preselection, K8S cluster high-availability preselection, node resource reservation preselection, and container resource preselection. Among them, the rack high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two racks, the data center high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two data centers, the K8S cluster high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two K8S clusters, the node resource reservation preselection is used to preselect that the container nodes reserve a preset percentage of resources, and the container resource preselection is used to preselect that the resources of the container nodes meet the preset requirements.
[0172] In a possible implementation, the second policy includes a container node load scoring policy, a service affinity scoring policy, and a host-level high availability scoring policy for workloads. Among them, the container node load scoring policy scores based on the real-time resource utilization of container nodes, the service affinity scoring policy scores based on the affinity between container nodes on the same data center, and the host-level high availability scoring policy for workloads scores based on the situation of container nodes under the same workload located on hosts.
[0173] In a possible implementation, the second configuration information includes the environment variables of the application, RBAC permissions, and preset configurations for scheduling.
[0174] The device provided by the embodiments of the present application can be used to execute the technical solutions of the above method embodiments. The implementation principles and technical effects are similar, and will not be elaborated here in the embodiments of the present application.
[0175] Optionally, Figure 10 A possible basic hardware architecture of the application publishing system described in the present application is schematically provided.
[0176] See Figure 10 , the application publishing system 1000 includes at least one processor 1001 and a communication interface 1003. Further optionally, a memory 1002 and a bus 1004 may also be included.
[0177] Among them, the application publishing system 1000 may be the above-mentioned processing device, and the present application does not make special restrictions on this. In the application publishing system 1000, the number of processors 1001 may be one or more, Figure 10 only one processor 1001 is schematically shown. Optionally, the processor 1001 may be a central processing unit (CPU), a graphics processing unit (GPU), or a digital signal processor (DSP). If the application publishing system 1000 has multiple processors 1001, the types of the multiple processors 1001 may be different or the same. Optionally, the multiple processors 1001 of the application publishing system 1000 may also be integrated into a multi-core processor.
[0178] The memory 1002 stores computer instructions and data; the memory 1002 may store computer instructions and data required to implement the above-mentioned application management method provided in the present application, for example, the memory 1002 stores instructions for implementing the steps of the above-mentioned application management method. The memory 1002 may be any one or any combination of the following storage media: non-volatile memory (e.g., read-only memory (ROM), solid-state drive (SSD), hard disk (HDD), optical disk), volatile memory.
[0179] The communication interface 1003 can provide information input / output for the at least one processor, and can also include any one or any combination of the following devices: a network interface (eg, an Ethernet interface), a wireless network card, and other devices with network access functions.
[0180] Optionally, the communication interface 1003 may also be used for data communication between the application publishing system 1000 and other computing devices or terminals.
[0181] Further optional, Figure 10 A thick line represents the bus 1004. The bus 1004 can connect the processor 1001 with the memory 1002 and the communication interface 1003. Thus, through the bus 1004, the processor 1001 can access the memory 1002, and can also use the communication interface 1003 to exchange data with other computing devices or terminals.
[0182] In the present application, the application publishing system 1000 executes computer instructions in the memory 1002, so that the application publishing system 1000 implements the above-mentioned application management method provided in the present application, or enables the application publishing system 1000 to deploy the above-mentioned application management device.
[0183] From the perspective of logical function division, for example, Figure 10 As shown, the memory 1002 may include an acquisition module 901, a first verification module 902, an addition module 903, and a second verification module 904. The inclusion here only refers to the fact that when the instructions stored in the memory are executed, the functions of the acquisition module, the first verification module, the addition module, and the second verification module can be realized respectively, and is not limited to the physical structure.
[0184] In addition, the above application publishing system can Figure 10 In addition to being implemented through software, it can also be implemented through hardware as a hardware module or as a circuit unit.
[0185] The present application provides a computer-readable storage medium, wherein the computer program product includes computer instructions, and the computer instructions instruct a computing device to execute the above-mentioned application management method provided by the present application.
[0186] The present application provides a computer program product, including computer instructions, which are executed by a processor to implement the above-mentioned application management method provided by the present application.
[0187] The present application provides a chip, including at least one processor and a communication interface, where the communication interface provides information input and / or output for the at least one processor. Further, the chip may further include at least one memory for storing computer instructions. The at least one processor is used to call and run the computer instructions to implement the above-mentioned application management method provided by the present application.
[0188] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0189] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0190] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit exists physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.
Claims
1. An application management method, characterized in that, The method is applied to an application release system, and the method includes: Obtain an application release request, and based on the application release request, obtain the first configuration information of the application to be released from the application management system; According to the application release request and the first configuration information, perform a first verification on the application to be released. If the first verification passes, release the workload of the application to be released to the K8S platform, so that the K8S platform creates containers according to the workload of the application to be released and triggers a creation callback to the application release system, where the K8S platform includes multiple K8S clusters; According to the creation callback, obtain the second configuration information of the application to be released from the application management system and add the second configuration information to the container; Obtain the resource status of the multiple K8S clusters from the application management system, and according to the resource status of the multiple K8S clusters, perform a second verification on the application to be released. If the second verification passes, send a container creation success message to the K8S platform, so that the K8S platform starts the container based on the container creation success message.
2. The method according to claim 1, wherein The application release request carries the identifier of the application to be released; The obtaining the first configuration information of the application to be released from the application management system based on the application release request includes: Based on the identifier of the application to be released, obtain the first configuration information of the application to be released from the application management system.
3. The method according to claim 2, characterized in that, The application release request also carries the release package of the application to be released, and the first configuration information includes the namespace, workload, and total computing resources used by the application to be released; The performing a first verification on the application to be released according to the application release request and the first configuration information includes: Verify the legality of the identifier of the application to be released; If the identifier of the application to be released is verified to be legal, parse the release package of the application to be released to obtain the namespace, workload, and total computing resources declared to be used by the application to be released; Respectively verify whether the namespace, workload, and total computing resources declared to be used by the application to be released are consistent with the namespace, workload, and total computing resources used by the application to be released.
4. The method according to any one of claims 1 to 3, characterized in that The resource status of the multiple K8S clusters includes the applied computing resources grouped by application for the multiple K8S clusters, and the applied computing resources include the type of resource object applied for, the number of containers generated, and the total computing resources of the generated containers; The performing a second verification on the application to be released according to the resource status of the multiple K8S clusters includes: According to the resource status of the multiple K8S clusters, determine the type of resource object applied for by the application to be released, the number of containers generated, and the total computing resources of the generated containers; Verify whether the resource object type of the to-be-released application request exceeds the resource object type of the to-be-released application application, whether the number of containers generated by the to-be-released application request exceeds the number of containers generated by the to-be-released application application, and verify whether the total computing resources of the containers generated by the to-be-released application request exceed the total computing resources of the containers generated by the to-be-released application application.
5. The method according to any one of claims 1 to 3, characterized in that Send the container creation success information to the K8S platform, so that the K8S platform starts the container based on the container creation success information, including: Send the container creation success information to the K8S platform, so that the K8S platform performs container node scheduling in the application management system based on the container creation success information to obtain the correspondence between the container node - physical machine - rack - data center, and based on the correspondence, the first policy and the second policy, determine the target container node and start the container.
6. The method according to claim 5, characterized in that The first policy includes rack high-availability preselection, data center high-availability preselection, K8S cluster high-availability preselection, node resource reservation preselection, and container resource preselection. Among them, the rack high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two racks, the data center high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two data centers, the K8S cluster high-availability preselection is used to preselect that the container nodes of a module in the application cluster are deployed on at least two K8S clusters, the node resource reservation preselection is used to preselect that the container nodes reserve a preset percentage of resources, and the container resource preselection is used to preselect that the resources of the container nodes meet the preset requirements.
7. The method according to claim 5, wherein The second policy includes a container node load scoring policy, a business affinity scoring policy, and a host-level high-availability scoring policy for the workload. Among them, the container node load scoring policy scores based on the real-time resource utilization of the container nodes, the business affinity scoring policy scores based on the affinity between the container nodes on the same data center, and the host-level high-availability scoring policy for the workload scores based on the situation of the container nodes under the same workload on the host.
8. The method according to any one of claims 1 to 3, characterized in that, The second configuration information includes the environment variables of the application, role-based access control permissions, and preset configurations for scheduling.
9. An application management device, characterized in that, The device is applied to an application release system, and the device includes: An acquisition module, configured to acquire an application release request, and based on the application release request, acquire the first configuration information of the to-be-released application from the application management system; A first verification module, configured to perform a first verification on the to-be-released application according to the application release request and the first configuration information. If the first verification passes, publish the workload of the to-be-released application to the K8S platform, so that the K8S platform creates a container according to the workload of the to-be-released application and triggers a creation callback to the application release system, where the K8S platform includes multiple K8S clusters; An adding module, configured to obtain second configuration information of the application to be released from the application management system according to the created callback, and add the second configuration information to the container; A second verification module, configured to obtain resource statuses of the multiple K8S clusters from the application management system, and perform a second verification on the application to be released according to the resource statuses of the multiple K8S clusters. If the second verification is passed, a container creation success message is sent to the K8S platform, so that the K8S platform starts the container based on the container creation success message.
10. An application publishing system, characterized in that, Comprising: A processor; A memory; And A computer program; Wherein, the computer program is stored in the memory and is configured to be executed by the processor. The computer program includes instructions for executing the method according to any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program causes the server to execute the method according to any one of claims 1-8.
12. A computer program product, characterized in that, Including computer instructions, and the computer instructions are executed by the processor to execute the method according to any one of claims 1-8.
Citation Information
Patent Citations
Resource group configuration method and system, equipment, and medium
CN112463384A
Data verification method and device based on K8S container platform
CN113626307A