Business management method, apparatus, device, and medium
By combining a pre-defined relationship table with a general business testing procedure, the problems of large workload and delay in business environment testing are solved, achieving efficient and flexible environment testing and improving the security and stability of the business environment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2022-01-05
- Publication Date
- 2026-06-26
AI Technical Summary
In existing technologies, business environment detection requires a lot of manpower to write detection scripts, has a large workload, and has a long detection feedback delay.
By storing the mapping relationship between the running sub-environment information, container image information and test instance information through a pre-defined relationship table, the environment is tested using a general business test program combined with the detection indicator information, reducing the need for writing specific scripts.
This eliminates the need to write specific testing scripts for each business service device, reducing the workload of business environment testing, improving the response rate and flexibility of environment testing, and enhancing the security and stability of the business environment.
Smart Images

Figure CN116414684B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computers, and more particularly to a business management method, apparatus, device, and medium. Background Technology
[0002] With the increasing application of the Internet, cybersecurity (such as payment security) for various business services is receiving more and more attention.
[0003] In related technologies, a common approach is to write specific business environment detection scripts for each business service device, and then perform corresponding business environment checks based on these scripts. This not only requires a significant amount of manpower to write the detection scripts, but also results in a large workload for detection and delays in feedback. Summary of the Invention
[0004] This disclosure provides a business management method, apparatus, equipment, and medium to solve at least one technical problem in the prior art.
[0005] On the one hand, this disclosure provides a business management method, including:
[0006] In response to a business detection request, obtain at least one runtime sub-environment information corresponding to the target business;
[0007] From a preset relationship table, query at least one target container image and at least one target test instance that match each of the runtime sub-environment information; the preset relationship table stores at least the mapping relationship between runtime sub-environment information, container image information, and test instance information;
[0008] Obtain at least one detection metric information corresponding to the target container image information, and send the detection metric information and the corresponding target test instance information to the general business test program;
[0009] The general business testing program is invoked so that it can perform testing on at least one of the running sub-environments based on the detection index information and the corresponding target test instance information.
[0010] The environmental detection results corresponding to the target service sent by the general service test program are obtained in order to realize environmental detection management of the target service.
[0011] On the other hand, a business management device is also provided, the device comprising:
[0012] The first acquisition module is used to acquire at least one runtime sub-environment information corresponding to the target business in response to a business detection request.
[0013] The query module is used to query at least one target container image information and at least one target test instance information that match each of the runtime sub-environment information from a preset relationship table; the preset relationship table stores at least the mapping relationship between runtime sub-environment information, container image information and test instance information;
[0014] The processing module is used to obtain detection indicator information corresponding to at least one of the target container image information, and send the detection indicator information and the corresponding target test instance information to the general business test program;
[0015] The calling module is used to call the general business test program so that the general business test program can perform detection on at least one of the running sub-environments based on the detection indicator information and the corresponding target test instance information;
[0016] The second acquisition module is used to obtain the environmental detection results corresponding to the target service sent by the general service test program, so as to realize environmental detection management of the target service.
[0017] On the other hand, an electronic device is also provided, the electronic device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement any of the methods described above.
[0018] On the other hand, a computer-readable storage medium is also provided, wherein at least one instruction or at least one program is stored therein, the at least one instruction or the at least one program being loaded and executed by a processor to implement any of the methods described above.
[0019] On the other hand, a computer program product or computer program is also provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform any of the methods described above.
[0020] The business management method, apparatus, equipment, and medium disclosed herein have the following technical advantages:
[0021] In this embodiment, a preset relationship table stores at least the mapping relationships between runtime sub-environment information, container image information, and test instance information. Based on at least one runtime sub-environment information corresponding to the target service, the corresponding target container image information and target test instance information are obtained from this preset relationship table. Then, by combining a general business testing program with the detection indicator information corresponding to the target container image information, the runtime sub-environment is tested. This eliminates the need to write specific business environment testing scripts for each business service device, reducing the workload of business environment testing and improving the environment detection response rate. Furthermore, by maintaining and modifying the preset relationship table, customized business environment testing can be implemented for different business directions, improving the flexibility and scalability of business testing, enabling rapid access to multiple services and scenarios, and thus contributing to improved business environment security and stability. Attached Figure Description
[0022] To more clearly illustrate the technical solutions and advantages in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of the application environment of a business management method provided in an embodiment of this disclosure;
[0024] Figure 2 This is a flowchart illustrating a business management method provided in an embodiment of this disclosure;
[0025] Figure 3 This is a partial flowchart illustrating a business management method provided in an embodiment of this disclosure;
[0026] Figure 4 This is a partial flowchart illustrating a business management method provided in an embodiment of this disclosure;
[0027] Figure 5 This is a partial flowchart illustrating a business management method provided in an embodiment of this disclosure;
[0028] Figure 6 This is a schematic diagram of a business management method provided in an embodiment of this disclosure;
[0029] Figure 7 This is a partial flowchart illustrating a business management method provided in an embodiment of this disclosure;
[0030] Figure 8 This is a structural block diagram of a business management method apparatus provided in an embodiment of this disclosure;
[0031] Figure 9 This is a schematic diagram of the hardware structure of a device for implementing the method provided in the embodiments of this disclosure. Detailed Implementation
[0032] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.
[0033] To make the objectives, technical solutions, and advantages of this disclosure clearer, the embodiments of this disclosure will be described in further detail below with reference to the accompanying drawings.
[0034] To facilitate understanding of the technical solutions described above and their resulting technical effects in the embodiments of this disclosure, the terms used in the embodiments of this disclosure are briefly introduced as follows:
[0035] Cloud technology is a collective term for network technologies, information technologies, integration technologies, management platform technologies, and application technologies applied to the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can be achieved through cloud computing.
[0036] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a large network of clients, it monitors abnormal software behavior on the network, obtains the latest information on Trojans and malware on the internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.
[0037] The main research directions in cloud security include: 1. Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control network-wide security events and risks; 3. Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services.
[0038] Cloud storage is a new concept that extends and develops from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as a storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of storage devices of various types (storage devices are also called storage nodes) in the network to work together through application software or application interfaces to provide data storage and business access functions to the outside world.
[0039] Currently, the storage method in storage systems is as follows: Logical volumes are created, and during creation, physical storage space is allocated to each logical volume. This physical storage space may consist of a single storage device or the disks of several storage devices. Clients store data on a logical volume, which means storing the data on the file system. The file system divides the data into many parts, each part being an object. Each object contains not only the data but also additional information such as a data identifier (ID, IDentity). The file system writes each object to the physical storage space of that logical volume, and it records the storage location information of each object. Therefore, when a client requests access to data, the file system can allow the client to access the data based on the storage location information of each object.
[0040] The process by which a storage system allocates physical storage space to a logical volume is as follows: the physical storage space is pre-divided into strips according to the capacity estimate of the objects stored in the logical volume (this estimate often has a large margin relative to the actual capacity of the objects to be stored) and the grouping of Redundant Array of Independent Disks (RAID). A logical volume can be understood as a strip, thus allocating physical storage space to the logical volume.
[0041] A database, simply put, can be viewed as an electronic filing cabinet—a place to store electronic files, where users can perform operations such as adding, querying, updating, and deleting data. A "database" is a collection of data stored together in a certain way, capable of being shared by multiple users, with minimal redundancy, and independent of application programs.
[0042] A Database Management System (DBMS) is a computer software system designed to manage databases, generally possessing basic functions such as storage, retrieval, security, and backup. DBMSs can be classified according to the database model they support, such as relational or XML (Extensible Markup Language); or according to the type of computer they support, such as server clusters or mobile phones; or according to the query language used, such as SQL (Structured Query Language) or XQuery; or according to performance priorities, such as maximum scale or maximum operating speed; or other classification methods. Regardless of the classification method used, some DBMSs can cross categories, for example, simultaneously supporting multiple query languages. The solutions provided in this disclosure relate to technologies such as cloud technology, and are specifically described through the following embodiments.
[0043] The business management methods disclosed herein can be applied to, for example... Figure 1 The application environment shown. For example... Figure 1 As shown, the hardware environment may include at least terminal 10, server 20, and server 30.
[0044] The aforementioned terminal 10 can be a smartphone, tablet computer, laptop computer, desktop computer, smart speaker, smartwatch, in-vehicle terminal, smart TV, etc., but is not limited to these.
[0045] The aforementioned servers 20 and 30 can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services. Terminals and servers can be connected directly or indirectly via wired or wireless communication, and this disclosure does not impose any limitations. It should be noted that the aforementioned servers 20 and 30 can be implemented as cloud servers in the cloud.
[0046] In some embodiments, servers 20 and 30 can also be implemented as nodes in a blockchain system. Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and cryptographic algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer.
[0047] It should be noted that in practical applications, the above business management methods can also be implemented on the server, or jointly implemented by the terminal and a server.
[0048] Of course, the methods provided in this disclosure are not limited to... Figure 1 The hardware environment shown can also be used in other possible hardware environments, and this disclosure does not limit the scope of the embodiments. Figure 1 The functions that each device in the hardware environment shown can perform will be described in subsequent method embodiments, and will not be elaborated on here.
[0049] Figure 2 This is a flowchart illustrating a business management method provided in an embodiment of this disclosure. Figure 6 This is a schematic diagram of a business management method provided in an embodiment of this disclosure. This disclosure provides the operational steps of the method described in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many steps and does not represent a unique execution order. The executing entity of this business management method can be the business management device provided in the embodiments of this disclosure, or a server integrating the business management device, wherein the business management device can be implemented in hardware or software. Taking the above-mentioned executing entity as an example... Figure 1 Let's take the server in the example of this as an illustration. Figure 2 and Figure 6 As shown, the method may include:
[0050] S201: In response to a service detection request, obtain at least one runtime sub-environment information corresponding to the target service.
[0051] The business detection request can be sent proactively by the terminal or server running the target business, or it can be sent automatically according to the inspection frequency (e.g., every 3 minutes). This disclosure does not make any specific limitations on this.
[0052] The target business refers to businesses that require secure management of their operational environment, such as payment services, fund transfer services, wealth management services, login services, and email services. The operational environment for each target business can include at least one sub-environment. Taking the payment business as an example, its operational environment can include a payment intermediary sub-environment, a risk control sub-environment, and an asset sub-environment.
[0053] In practical applications, after receiving a business detection request, if the request includes environment identification information (e.g., environment ID), it can be parsed to obtain at least one operational sub-environment information corresponding to the target business. If the request does not include environment identification information, all alarm environments in the record table can be queried, such as environments with an attribute status of "1". For example, this operational sub-environment information may include a sub-environment ID, which can be used for unique environment identification.
[0054] S203: From the preset relationship table, query at least one target container image and at least one target test instance that match each running sub-environment information.
[0055] The preset relationship table stores at least the mapping relationship between the running sub-environment information, container image information, and test instance information.
[0056] The container image information includes the environment build scripts for the target service runtime and the required resource data. This container image information includes, but is not limited to, the container image name and container image address. The test instance information points to the test instance scripts that perform security checks on the runtime sub-environment. This test instance information may include, but is not limited to, the test instance IP address, so that the corresponding tests can be performed by calling the test instance corresponding to that IP address. The same runtime sub-environment can correspond to different container images, and the same container image can correspond to different test instances; this disclosure does not impose specific limitations in this regard.
[0057] The preset relationship table can be pre-built so that when needed, the corresponding target container image information and at least one target test instance information can be determined directly based on the mapping relationship between the runtime sub-environment information, container image information and test instance information recorded in the preset relationship table, using at least one runtime sub-environment information.
[0058] In practical applications, multiple sets of preset relationship tables can be deployed to meet the needs of different testing environments. For example, there can be preset relationship tables for development environments (DEV environments) and preset relationship tables for data center environments (IDC environments). By traversing the information of each running sub-environment, the preset relationship tables are used to sequentially query at least one target container image information (e.g., image ID) and at least one target test instance information (e.g., instance IP) that match each running sub-environment information.
[0059] S205: Obtain the detection metric information corresponding to at least one target container image, and send the detection metric information and the corresponding target test instance information to the general business test program.
[0060] Optionally, after obtaining the target container image information for each running sub-environment, the corresponding detection metric information can be queried from a pre-built image table. This detection metric information is used to characterize the reference threshold or reference threshold range corresponding to a certain detection metric parameter.
[0061] Next, the detection metric information and the corresponding target test instance information can be sent to the general business test program. This general business test program can be a generic detection toolkit installed on the terminal being tested; that is, all business test programs on each terminal being tested are identical. The general business test program can include various local commands for executing services such as inspection services, and return the corresponding detection results after the test is completed.
[0062] In one optional implementation, the detection indicator information includes at least one detection type and a corresponding detection reference value for each detection type. The detection type may include, but is not limited to, at least one type such as process, port, CC (service and resource routing information), BC (service configuration information), key, network policy, and use case. Each detection type has a corresponding specific detection item, and each specific detection item may correspond to a detection reference value. It should be understood that the detection reference value here may be a reference threshold, a reference range, or other applicable data, and this disclosure does not specifically limit it.
[0063] Optionally, this testing indicator information can be configured by administrators. For example, based on the actual needs of the target business, the required testing type can be selected, and specific testing items can be configured for different testing types. After configuration, the newly configured information can be inserted into the corresponding backend database. When testing the target business, the relevant data can be retrieved from this database in real time, thus enabling the newly added testing indicator information to take effect immediately and perform the corresponding testing.
[0064] Correspondingly, continue as Figure 6As shown, after obtaining the detection index information corresponding to at least one of the target container image information, the method may further include: configuring the detection status data as initial state data for each detection type; and modifying the corresponding detection status data to target state data when an environmental detection result is obtained. Optionally, the initial state data is used to represent the state data of "start detection", and the target state data is used to represent the state data such as "end detection", "detection result normal", or "detection result abnormal". It should be noted that the initial state data and target state data can be represented by, for example, numbers or letters. This facilitates subsequent management of each task and execution of corresponding business management based on the detection status data.
[0065] S207: Invoke the general business test program so that the general business test program can perform tests on at least one running sub-environment based on the detection indicator information and the corresponding target test instance information.
[0066] Optionally, by calling the interface corresponding to the general business test program, the general business test program can use the target test instance information corresponding to each container image to test at least one running sub-environment and obtain test result information. Then, by combining the test indicator information and the corresponding test result information corresponding to each container image, the environment test result of whether each running sub-environment is normal is obtained.
[0067] S209: Obtain the environmental detection results corresponding to the target service sent by the general service test program, so as to realize environmental detection management of the target service.
[0068] Optionally, after obtaining the environmental detection results corresponding to the target business returned by the general business testing program, an environmental alarm message can be generated and recorded when the environmental detection result is an abnormal environment, and the environmental alarm message can be pushed to the relevant personnel for maintenance, thereby realizing environmental detection management of the target business.
[0069] In the above embodiments, since the preset relationship table stores at least the mapping relationship between runtime sub-environment information, container image information, and test instance information, the corresponding target container image information and target test instance information are obtained from the preset relationship table based on at least one runtime sub-environment information corresponding to the target service. Then, by combining the detection indicator information corresponding to the target container image information with a general business testing program, the runtime sub-environment is tested. This eliminates the need to write specific business environment detection scripts for each business service device, reducing the workload of business environment testing and improving the environment detection response rate. Furthermore, by maintaining and modifying the preset relationship table, customized business environment testing can be implemented for different business directions, improving the flexibility and scalability of business testing, enabling rapid access to multiple services and scenarios, and thus improving the security and reliability of the business environment.
[0070] In an optional implementation, after obtaining at least one operating sub-environment information corresponding to the target service, the method further includes: generating detection task identification information for each operating sub-environment information; reconstructing the operating environment to be detected corresponding to the target service based on the detection task identification information; and determining that the operating environment to be detected is an abnormal environment if the environment reconstruction fails, and using it as the environment detection result corresponding to the target service.
[0071] Optionally, continue as follows Figure 6 As shown, after obtaining at least one runtime sub-environment information, a detection task identifier can be generated for each runtime sub-environment, such as task n (n is a positive integer). Since each runtime sub-environment can correspond to multiple container images, to facilitate subsequent business management, all image detection subtasks corresponding to each runtime sub-environment can be aggregated into one detection task, and a corresponding detection task identifier (e.g., task id) can be assigned to this detection task. Then, based on this detection task identifier, the runtime environment to be detected corresponding to the target business is reconstructed. If the environment reconstruction fails, the runtime environment to be detected can be determined to be an abnormal environment, and this abnormal environment can be used as the environment detection result corresponding to the target business, without needing to execute subsequent test steps. If the environment reconstruction is successful, step S203 and subsequent test steps are executed. In this way, by reconstructing the runtime environment, the abnormality of the runtime environment can be quickly detected, improving business detection efficiency and facilitating rapid anomaly response.
[0072] In an alternative implementation, such as Figure 3 As shown, after the step of obtaining the environment detection result corresponding to the target service sent by the general service test program, the method further includes:
[0073] S301: If the environmental detection result corresponding to the target service is determined to be abnormal, the first exception handling module is called to perform exception recovery processing on the operating environment corresponding to the target service, so as to realize the exception management of the target service.
[0074] The anomaly recovery process may include at least one anomaly recovery strategy, such as data cleanup, program upgrade, and image update.
[0075] Optionally, such as Figure 4As shown, upon the initial inspection alarm, the recovery script information corresponding to the anomaly can be queried. Typically, one inspection rule corresponds to one recovery script. Next, based on this recovery script information, the corresponding recovery strategy can be read from the recovery strategy library. After obtaining the corresponding recovery strategy, anomaly recovery processing can be executed according to that strategy. If no suitable recovery strategy is obtained, a general recovery strategy can be used to execute the anomaly recovery processing. Furthermore, before performing anomaly recovery processing, the attribute status of the target service's operating environment can be recorded as "initial recovery" (recovery initial state). Then, a recovery request can be sent to the first anomaly handling module, enabling it to perform anomaly recovery processing on the target service's operating environment, thus achieving anomaly management for the target service. After completing the anomaly recovery processing, the attribute status of the target service's operating environment can be recorded as "post-recovery." Then, it is determined whether the recovery result is successful. If the result is successful, the attribute status of the target service's operating environment is updated.
[0076] In an optional implementation, the step of invoking the first exception handling module to perform exception recovery processing on the runtime environment corresponding to the target service includes:
[0077] S3011: Invoke the first exception handling module to perform data cleanup processing on the operating device corresponding to the target service;
[0078] S3013: If it is determined that the operating environment corresponding to the target service after data cleaning has not been restored to normal, query the latest service program version corresponding to the target service;
[0079] S3015: Use the latest service program version to upgrade the program of the operating device corresponding to the target service;
[0080] S3017: If it is determined that the operating environment corresponding to the target service that has been upgraded by the program has not been restored to normal, obtain the latest container image corresponding to the target service;
[0081] S3019: Using the latest container image, update the image corresponding to the runtime environment of the target service to achieve abnormal recovery of the runtime environment corresponding to the target service.
[0082] Optionally, continue as follows Figure 4As shown, when the environment detection result indicates an environment anomaly, data cleanup can be performed first, such as disk cleanup, memory cleanup, and other machine resource cleanup operations. Then, the service is restarted, and it is determined whether the runtime environment corresponding to the target business has returned to normal. If not, the latest service program version corresponding to the target business is checked for recent updates; if so, the latest service program version is deployed. Then, the runtime environment corresponding to the target business is checked again; if it still hasn't returned to normal, the container image corresponding to the target business is updated to the latest container image. Typically, when submitting images to the repository, it is necessary to ensure the availability of all business services to guarantee the recovery of the service environment. In this way, when an environment anomaly is detected, different anomaly recovery strategies are executed sequentially to restore the runtime environment of the target business, achieving automatic recovery of the anomaly alert environment and improving the security and reliability of the target business's runtime environment.
[0083] In an alternative implementation, such as Figure 5 As shown, after invoking the first exception handling module to perform exception recovery processing on the runtime environment corresponding to the target service, the method may further include:
[0084] S501: Obtain the environment type corresponding to the target service, and determine the environment anomaly type corresponding to the abnormal environment based on the environment type;
[0085] S503: Establish a recovery mapping relationship between environmental anomaly types and corresponding target anomaly recovery strategies; the target anomaly recovery strategy is used to characterize the modification strategy that restores the operating environment of the business to normal.
[0086] S505: Based on the recovery mapping relationship, determine the target anomaly recovery strategy corresponding to the operating environment of the target service;
[0087] S507: Call the second exception handling module and use the target exception recovery strategy to perform exception recovery processing on the runtime environment corresponding to the target business.
[0088] Optionally, in the initial stage of environment recovery, a general exception recovery strategy is configured. After the recovery problem is completed, the exception recovery strategy is recorded as a set of recovery strategies based on the exception module and the corresponding error code.
[0089] After accumulating sufficient recovery samples, the second exception handling module corresponding to the exception recovery strategy can learn the target exception recovery strategy for different error codes. Subsequently, in the same or similar scenarios, a better target exception recovery strategy can be automatically obtained. The second exception handling module adopts this target exception recovery strategy for exception recovery processing, reducing the exception recovery time. This achieves rapid self-healing of the operating environment corresponding to the target business, further improving the security and reliability of the target business's operating environment.
[0090] S303: If the environmental detection results corresponding to the target service are determined to be normal, calculate the environmental indicator information of the operating environment corresponding to the target service.
[0091] The environmental indicator information is used to characterize the health of the operating environment in the current detection cycle.
[0092] The environmental metrics information can be measured by at least one of the following dimensions: processes, TCP ports, UDP ports, network policies, configurations, etc. The environmental metrics information can be measured by scores or levels.
[0093] In an optional implementation, when the environmental indicator information includes multiple indicator dimensions, the environmental indicator information for calculating the operating environment corresponding to the target service includes:
[0094] S3031: Obtain the weight corresponding to each type of environmental indicator information;
[0095] S3033: Weight each type of environmental indicator information based on weights to obtain the environmental indicator information of the operating environment corresponding to the target business.
[0096] Optionally, the weight of each type of environmental indicator is proportional to its importance to the health of the environment. For example, for the five types of environmental indicators—process, TCP port, UDP port, network policy, and configuration—their respective weights are 10%, 10%, 20%, 30%, and 30%. Subsequently, the scores for each type of environmental indicator obtained in a single test are 100, 100, 90, 80, and 80 points respectively. The final environmental indicator is the weighted sum of each type of indicator, i.e., 100*10% + 100*10% + 90*20% + 80*30% + 80*30% = 86 points. By considering the weight of each type of environmental indicator and weighting it accordingly, the obtained environmental indicator information better reflects the current health of the business environment, improving the sensitivity and accuracy of business environment detection.
[0097] In an alternative implementation, continue as follows Figure 6 As shown, after the step of calculating the environmental indicator information of the operating environment corresponding to the target service, the method further includes:
[0098] If the environmental indicators corresponding to the target business meet the preset environmental indicator conditions, check whether the operating environment corresponding to the target business has returned to normal in the next detection cycle.
[0099] Once it is determined that the operating environment corresponding to the target service has returned to normal, the recovery status of the operating environment corresponding to the target service is sent to the second exception handling module;
[0100] If it is determined that the operating environment corresponding to the target business has not returned to normal, test cases are executed to detect the operating environment corresponding to the target business.
[0101] Optionally, continue as follows Figure 6 As shown, if the environmental indicators for the current detection cycle meet the preset environmental indicator conditions, the next detection cycle checks whether the operating environment corresponding to the target service has returned to normal. If it is determined that the operating environment corresponding to the target service has returned to normal, the recovery status is sent to the second exception handling module so that the second exception handling module can record and learn the recovery status. If it is determined that the operating environment corresponding to the target service has not returned to normal, it means that the current test instance detection has failed to find a valid problem. Test cases can be executed on the operating environment corresponding to the target service to call test cases to perform deeper asynchronous detection on the operating environment corresponding to the target service. After the asynchronous detection is completed, a task identifier is returned. In this way, by using multiple detection strategies and repeated environment detection, flexible detection of the business environment is achieved while reducing the detection workload, further improving the efficiency and reliability of environment detection.
[0102] In an optional implementation, the method further includes: configuring attribute states for each management node during the management process of the target service; different management nodes correspond to different attribute states.
[0103] The management node includes at least one of a test node, an anomaly recovery node, and at least one anomaly recovery processing node. This attribute status can be represented by, for example, numbers or letters, and this disclosure does not specifically limit its representation.
[0104] For example, such as Figure 7 As shown, the configuration attribute status can include:
[0105] a) When an environmental anomaly is discovered during inspection, the anomaly is recorded. At this time, the attribute status is 0.
[0106] b) If the anomaly is found to persist during the next inspection, the attribute status is updated to 1 and an alarm message is sent.
[0107] c) After sending the alarm, the program will create an alarm group according to business requirements, record the alarm information to the management backend, and update the attribute status to 2 at the same time.
[0108] d) Regarding the automatic recovery issue during environmental inspection, the status in the management backend has been changed to "recovering," and the backend asynchronously updates the attribute status to 3.
[0109] e) Environmental inspection automatic recovery process: If the problem is resolved after restarting, the status in the management backend will be changed to "recovered", and the attribute status will be updated asynchronously to 4 in the backend.
[0110] f) Automatic recovery process for environment inspection: If the problem is recovered after version deployment, the status in the management backend will be changed to "recovered", and the attribute status will be updated asynchronously to 5 in the backend.
[0111] g) Automatic recovery process for environmental inspection: If recovery is only performed when the image is last updated, the status in the management backend will be changed to "recovered" and the attribute status will be updated asynchronously to 6.
[0112] The above describes how attribute statuses are configured for each management node in the management process of the target business. Different management nodes have different attribute statuses, so all issues are connected to the management backend. The management backend can realize the flow of issue statuses based on the attribute statuses of each node, thereby completing the closed loop of abnormal issues and completely resolving them.
[0113] The following are embodiments of the apparatus disclosed herein, which can be used to execute embodiments of the method disclosed herein. For details not disclosed in the apparatus embodiments of this disclosure, please refer to the embodiments of the method disclosed herein.
[0114] Please refer to Figure 8 This diagram illustrates a structural block diagram of a business management device provided in an embodiment of this disclosure. The device has the functions described in the method example above; these functions can be implemented in hardware or by hardware executing corresponding software. The business management device may include:
[0115] The first acquisition module 810 is used to acquire at least one running sub-environment information corresponding to the target business in response to a business detection request.
[0116] The query module 820 is used to query at least one target container image information and at least one target test instance information that match each of the runtime sub-environment information from a preset relationship table; the preset relationship table at least stores the mapping relationship between runtime sub-environment information, container image information and test instance information;
[0117] Processing module 830 is used to obtain at least one detection indicator information corresponding to the target container image information, and send the detection indicator information and the corresponding target test instance information to the general business test program;
[0118] The calling module 840 is used to call the general business test program so that the general business test program can detect at least one of the running sub-environments based on the detection index information and the corresponding target test instance information.
[0119] The second acquisition module 850 is used to obtain the environmental detection results corresponding to the target service sent by the general service test program, so as to realize environmental detection management of the target service.
[0120] In an alternative embodiment, the apparatus further includes:
[0121] The generation module is used to generate detection task identification information for each of the aforementioned operating sub-environment information;
[0122] The reconstruction module is used to reconstruct the operating environment to be detected corresponding to the target service based on the detection task identification information.
[0123] The result determination module is used to determine that the operating environment to be detected is an abnormal environment when the environment reconstruction fails, and to use it as the environment detection result corresponding to the target service.
[0124] In one optional embodiment, the detection index information includes at least one detection type and a detection reference value corresponding to each detection type; the device further includes:
[0125] The state configuration module is used to configure the detection state data as initial state data for each detection type.
[0126] The state modification module is used to modify the corresponding detection state data to target state data when the environmental detection result is obtained.
[0127] In an alternative embodiment, the apparatus further includes:
[0128] The anomaly recovery module is used to call the first anomaly handling module to perform anomaly recovery processing on the operating environment corresponding to the target service when the environment detection result corresponding to the target service is determined to be abnormal, so as to realize anomaly management of the target service.
[0129] The indicator calculation module is used to calculate the environmental indicator information of the operating environment corresponding to the target service when the environmental detection result is determined to be normal. The environmental indicator information is used to characterize the health of the operating environment in the current detection cycle.
[0130] In an optional implementation, when the environmental indicator information includes multiple indicator dimensions, the indicator calculation includes:
[0131] The weight acquisition submodule is used to obtain the weight corresponding to each type of environmental indicator information;
[0132] The indicator calculation submodule is used to perform weighted processing on each type of environmental indicator information based on the weights to obtain the environmental indicator information of the operating environment corresponding to the target business.
[0133] In an alternative embodiment, the apparatus further includes:
[0134] The recovery check module is used to check whether the operating environment corresponding to the target service has returned to normal in the next detection cycle if the environmental indicator information corresponding to the target service meets the preset environmental indicator conditions.
[0135] The sending module is used to send the recovery status of the operating environment corresponding to the target service to the second exception handling module when it is determined that the operating environment corresponding to the target service has been restored to normal.
[0136] The testing module is used to perform test cases to detect the operating environment corresponding to the target service if it is determined that the operating environment corresponding to the target service has not returned to normal.
[0137] In one optional implementation, the anomaly recovery module includes:
[0138] The first processing submodule is used to call the first exception handling module to perform data cleaning processing on the running device corresponding to the target service;
[0139] The query submodule is used to query the latest service program version corresponding to the target service if it is determined that the operating environment corresponding to the target service after data cleaning has not been restored to normal.
[0140] The second processing submodule is used to upgrade the operating device corresponding to the target service using the latest service program version.
[0141] The acquisition submodule is used to acquire the latest container image corresponding to the target service if it is determined that the operating environment corresponding to the target service that has been upgraded by the program has not been restored to normal.
[0142] The third processing submodule is used to update the image corresponding to the runtime environment of the target service using the latest container image, so as to realize the abnormal recovery of the runtime environment corresponding to the target service.
[0143] In an alternative embodiment, the apparatus further includes:
[0144] The status configuration module is used to configure the attribute status of each management node during the management process of the target service; different management nodes correspond to different attribute statuses. The management nodes include at least one of the following: test nodes, nodes in the process of anomaly recovery, and at least one anomaly recovery processing node.
[0145] The apparatus provided in the above embodiments can execute the corresponding methods in the embodiments of this disclosure, and has the corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in the above embodiments can be found in the methods provided in any embodiment of this application.
[0146] This disclosure provides a computer device that may include a processor and a memory. The memory stores at least one instruction, at least one program, a code set, or an instruction set. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the method described in any of the above method embodiments.
[0147] This disclosure also provides a computer-readable storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded by a processor and executed by any of the methods described in the above method embodiments.
[0148] This disclosure also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform any of the methods described in this embodiment.
[0149] Furthermore, Figure 9 A schematic diagram of a hardware structure for implementing the methods provided in the embodiments of this disclosure is shown. The device may be a computer terminal, a mobile terminal, or other device, and may also participate in or include the apparatus provided in the embodiments of this disclosure. Figure 9As shown, the computer terminal 11 may include one or more processors 112 (shown as 112a, 112b, ..., 112n in the figure) 112 (processor 112 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 114 for storing data, and a transmission device 116 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 9 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 11 may also include... Figure 9 The more or fewer components shown, or having the same Figure 9 The different configurations shown.
[0150] It should be noted that the aforementioned one or more processors 112 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 11 (or mobile device). As per the embodiments of this disclosure, the data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0151] The memory 114 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method described in this embodiment. The processor 112 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned neural network processing method. The memory 114 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 114 may further include memory remotely located relative to the processor 112, and these remote memories can be connected to the computer terminal 11 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0152] The transmission device 116 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 11. In one example, the transmission device 116 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 116 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0153] The display can be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 11 (or mobile device).
[0154] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments of this disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are also possible or may be advantageous.
[0155] The various embodiments in this disclosure are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and server embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0156] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0157] The above description is only a preferred embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.
Claims
1. A business management method, characterized in that, include: In response to a business detection request, obtain at least one runtime sub-environment information corresponding to the target business; From the preset relationship table, query at least one target container image and at least one target test instance that match each of the aforementioned running sub-environment information; The preset relationship table stores at least the mapping relationship between runtime sub-environment information, container image information, and test instance information; Obtain at least one detection metric information corresponding to the target container image information, and send the detection metric information and the corresponding target test instance information to the general business test program; The general business testing program is invoked so that it can perform testing on at least one of the running sub-environments based on the detection index information and the corresponding target test instance information. The environmental detection results corresponding to the target service sent by the general service test program are obtained in order to realize environmental detection management of the target service.
2. The method according to claim 1, characterized in that, After obtaining at least one runtime sub-environment information corresponding to the target service, the method further includes: Generate detection task identification information for each of the aforementioned operating sub-environment information; Based on the detection task identification information, the target service's corresponding operating environment is reconstructed. If the environment reconstruction fails, the operating environment to be tested is determined to be an abnormal environment and is used as the environment detection result corresponding to the target service.
3. The method according to claim 1, characterized in that, The detection index information includes at least one detection type and a corresponding detection reference value for each detection type; After obtaining the detection metric information corresponding to at least one of the target container image information, the method further includes: For each of the aforementioned detection types, configure the detection status data as initial state data; Upon obtaining the environmental detection results, the corresponding detection state data is modified to the target state data.
4. The method according to claim 1, characterized in that, After the step of obtaining the environment detection result corresponding to the target service sent by the general service test program, the method further includes: If the environmental detection result corresponding to the target service is determined to be abnormal, the first exception handling module is invoked to perform exception recovery processing on the operating environment corresponding to the target service, so as to realize the exception management of the target service. If the environmental detection result corresponding to the target service is determined to be normal, the environmental indicator information of the operating environment corresponding to the target service is calculated. The environmental indicator information is used to characterize the health of the operating environment in the current detection cycle.
5. The method according to claim 4, characterized in that, When the environmental indicator information includes multiple indicator dimensions, the environmental indicator information for calculating the operating environment corresponding to the target service includes: Obtain the weight corresponding to each type of environmental indicator information; Based on the weights, each type of environmental indicator information is weighted to obtain the environmental indicator information of the operating environment corresponding to the target business.
6. The method according to claim 4 or 5, characterized in that, After the step of calculating the environmental indicator information of the operating environment corresponding to the target service, the method further includes: If the environmental indicator information corresponding to the target service meets the preset environmental indicator conditions, the operating environment corresponding to the target service will be checked in the next detection cycle to see if it has returned to normal. If it is determined that the operating environment corresponding to the target service has been restored to normal, the restoration status of the operating environment corresponding to the target service is sent to the second exception handling module; If it is determined that the operating environment corresponding to the target service has not returned to normal, test cases are executed to detect the operating environment corresponding to the target service.
7. The method according to claim 4, characterized in that, The step of invoking the first exception handling module to perform exception recovery processing on the runtime environment corresponding to the target service includes: The first exception handling module is invoked to perform data cleanup processing on the operating device corresponding to the target service. If it is determined that the operating environment corresponding to the target business after data cleaning has not been restored to normal, query the latest service program version corresponding to the target business; The latest service program version is used to upgrade the operating equipment corresponding to the target service. If it is determined that the operating environment corresponding to the target service that has been upgraded by the program has not been restored to normal, obtain the latest container image corresponding to the target service; Using the latest container image, the image corresponding to the runtime environment of the target service is updated to achieve abnormal recovery of the runtime environment corresponding to the target service.
8. The method according to any one of claims 1-7, characterized in that, The method further includes: Configure attribute states for each management node during the management process of the target service; different management nodes correspond to different attribute states; The management node includes at least one of the following: a test node, an anomaly recovery node, and at least one anomaly recovery processing node.
9. A business management device, characterized in that, The device includes: The first acquisition module is used to acquire at least one runtime sub-environment information corresponding to the target business in response to a business detection request. The query module is used to query at least one target container image information and at least one target test instance information that match each of the runtime sub-environment information from a preset relationship table; the preset relationship table stores at least the mapping relationship between runtime sub-environment information, container image information and test instance information; The processing module is used to obtain detection indicator information corresponding to at least one of the target container image information, and send the detection indicator information and the corresponding target test instance information to the general business test program; The calling module is used to call the general business test program so that the general business test program can perform detection on at least one of the running sub-environments based on the detection indicator information and the corresponding target test instance information; The second acquisition module is used to obtain the environmental detection results corresponding to the target service sent by the general service test program, so as to realize environmental detection management of the target service.
10. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the business management method as described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the business management method as described in any one of claims 1-8.
12. A computer program product, characterized in that, The computer program product includes at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the business management method as described in any one of claims 1-8.