A Method and Device for Running Unikernel Based on Kubernetes
By managing the life cycle of Unikernel and connecting to Containerd and Kubernetes, the isolation and security problems of Unikernel in containers are solved, the vmfunc communication is optimized, and the efficiency and stability of container services are improved.
Patent Information
- Application Number
- CN202311113862.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-31
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-08-31
AI Technical Summary
The prior art has failed to effectively solve the access problem of Unikernel, resulting in insufficient isolation and security of containers, and the failure to fully utilize the accelerated communication functions provided by vmfunc.
Create a Unikernel structure by parsing the configuration file, start the daemon process and configure the environment, use IOCTL system calls to obtain the extended page table pointer information, manage the life cycle of Unikernel and connect to Containerd and Kubernetes, and optimize the runtime environment to support vmfunc communication.
It has achieved the improvement of Unikernel's security and isolation in containers, improved the efficiency and stability of container services, and optimized the communication efficiency between Unikernels.
Smart Images

Figure CN117272285B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cloud computing, and particularly relates to a method and device for running Unikernel based on Kubernetes. Background Art
[0002] With the rapid development of cloud computing and cloud service technologies, container technology has emerged as a key technology in the field of cloud computing. Container technology allows developers to package application programs and their dependent environments together, making the deployment and migration of application programs more convenient. At the same time, container technology also shows significant advantages in improving resource utilization, enhancing service scalability, and microservice architecture.
[0003] In this context, Kubernetes, as an open-source container orchestration platform, has been widely used. Kubernetes provides a complete set of distributed system support to help developers and operation and maintenance personnel better manage containerized application programs. For example, Chinese Patent with publication number CN115599492A discloses a method and system for simultaneously managing virtual machines and containers based on kubernetes. The method includes adding a virtual machine API service to the kubernetes API service to receive external virtual machine management requests; adding a virtual machine control component to the kubernetes cluster component to generate corresponding pods according to the received virtual machine requests; adding a virtual machine processing component to the kubernetes cluster node to monitor the state changes of each virtual machine instance on the node; adding a virtual machine running component to the kubernetes cluster node to manage a virtual machine in the corresponding pod, and the virtual machine running component communicates with libvirtd and provides virtual machine lifecycle management.
[0004] However, although container technology brings many benefits, it relies on operating system-level virtualization, resulting in deficiencies in isolation and security for containers. Therefore, Unikernel, as a lightweight operating system that packages application programs and operating system services together, has become a potential solution to enhance container security. However, how to integrate Unikernel into the existing container ecosystem, especially how to connect it to Containerd (an industrial-standard container runtime) and Kubernetes, is an unsolved problem.
[0005] Currently, the closest implementation solution may be to use tools similar to Kata Containers, which use lightweight virtual machines as a sandbox to run each container. For example, Chinese Patent with Publication No. CN115113984A discloses a container security solution method, system, electronic device and computer-readable storage medium based on a lightweight virtual machine to solve the problem that the container security tool is out of sync with the life cycle of the container. The container is a Kata container, and the method includes: integrating the container security tool into the virtual machine operating system Guest OS of the Kata container; when running the container, synchronously running the container security tool in the Guest OS corresponding to the container for container security detection, and synchronizing the life cycle of the container security tool with the life cycle of the container during the running process of the container. And, for example, Chinese Patent with Publication No. CN113297566A discloses a sandbox implementation method, device, equipment and storage medium, including: obtaining the target storage path of the target dynamic library file by the sandbox process; the target dynamic file includes a general interface for calling the target user-mode operating system; when the target dynamic library file is obtained according to the target storage path, the sandbox process configures the target user-mode operating system in the sandbox container corresponding to the sandbox process by calling the general interface. This application converts the general call method of user operations into the native call method of the target user-mode operating system through the general interface by the sandbox process, realizes the purpose of the sandbox process calling the target user-mode operating system, and can realize the operation control of different types of user-mode operating systems in the native operating system through a set of general call methods, so as to achieve the compatibility of multiple types of user-mode operating systems in a native operating system.
[0006] However, although this solution can improve isolation and security, it still fails to solve the problem of Unikernel access. In addition, this method also has limitations in dealing with vmfunc (vmfunc is an instruction for the virtual machine to switch the ept page table, ept: extended page tables, virtualization extended page tables, which record the mapping information from the virtual machine physical address to the host physical address) technology and cannot fully utilize the accelerated communication function provided by vmfunc. Therefore, seeking a new solution that can solve these problems has become an important task in the industry.
[0007] In summary, the existing technologies in this field currently mainly have the following disadvantages:
[0008] (1) Although container technology has advantages in improving deployment and migration efficiency, enhancing service scalability, etc., it has deficiencies in isolation and security, especially when facing complex and ever-changing security threats.
[0009] (2) Current implementation solutions, such as Kata Containers, although improving the isolation and security of containers, still fail to solve the access problem of Unikernel, resulting in the inability to fully utilize the advantages of Unikernel such as lightweight and high security.
[0010] (3) Existing container runtime management and optimization solutions have limitations in dealing with the vmfunc technology and cannot fully utilize the accelerated communication function provided by vmfunc. Summary of the Invention
[0011] The purpose of the present invention is to provide a method and device for running Unikernel based on Kubernetes, which can connect Unikernel to Containerd and connect to Kubernetes to improve the isolation and security of containers.
[0012] The present invention provides the following technical solutions:
[0013] A method for running Unikernel based on Kubernetes, the running method includes:
[0014] (1) Parse the configuration file and create a Unikernel structure to save the status information;
[0015] (2) According to the status information saved in step (1), start the daemon process of Unikernel, and then send a pause signal to the daemon process for subsequent recovery;
[0016] (3) After restoring the daemon process of the corresponding Unikernel, start the Unikernel process using the saved status information;
[0017] (4) After the Unikernel process starts, make the daemon process wait for the Unikernel process to exit;
[0018] (5) After the Unikernel process exits, delete the saved status information.
[0019] In step (1), the configuration file includes the startup command, environment variables, file system, mounts, and namespaces of Unikernel. The Unikernel structure includes the id of Unikernel, and the type of Unikernel is saved to the configuration file.
[0020] In step (2), after the daemon process starts, the following operations are performed:
[0021] (2-1) Use the IOCTL system call to obtain the extended page table pointer information of the unikernel according to the type of the unikernel;
[0022] (2-2) Perform environment configuration: prepare the network environment of the unikernel, prepare the file system environment of the unikernel, and prepare the startup command of the unikernel.
[0023] In step (2-2), the method of the environment configuration includes:
[0024] (2-2-1) Prepare the network environment of the unikernel: Add the unikernel process to the network namespace provided by the API interface of the container network in kubernetes;
[0025] (2-2-2) Prepare the file system environment of the unikernel: Check whether the format under the root directory folder is correct and process the corresponding mount items;
[0026] (2-2-3) Prepare the startup command of the unikernel: The startup command includes the kernel image file of the unikernel, file mounts, network ports, and resource limits.
[0027] Among them, the IOCTL (input / output control) system is used to interact with devices. In this application, it means creating a kernel device, and then using ioctl, information in the kernel can be obtained, such as extended page table pointer information.
[0028] Among them, the API interface of the container network is the CNI plugin, whose full name is Container Network Interface, that is, the API interface of the container network, which is a standard interface for calling network implementations in K8s.
[0029] In step (2), after the startup command is prepared, the daemon process receives the command to pause the startup of the unikernel process, and then saves the status information of the unikernel, the process id of the daemon process, and the extended page table pointer information corresponding to the unikernel.
[0030] Since the status information saved in step (1) is incomplete, the status information needs to be supplemented and improved in step (2).
[0031] In step (3), the method for the daemon process to start the Unikernel process is as follows: obtain the status information of the corresponding Unikernel according to the id of the Unikernel, restore it to the corresponding structure from the status information, and then send a command to the corresponding daemon process to restore the corresponding Unikernel process. At this time, the real Unikernel process starts; among them, the status information includes the status information saved in steps (1) and (2).
[0032] In step (4), when the daemon process waits for the Unikernel process to exit, the daemon process saves the status information of all running Unikernels. The specific method is as follows: traverse the status information of all Unikernels, and save the status information of all Unikernels after obtaining it through the status information.
[0033] In step (4), during the process of the Unikernel process exiting, the following operations need to be performed: stop the subprocess related to the Unikernel, send a signal that the subprocess has been stopped to Containerd, and handle the logic of Unikernel service cancellation.
[0034] The present invention also provides a Unikernel running device based on Kubernetes, including a memory and one or more processors. An executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement the above-mentioned Unikernel running method based on Kubernetes.
[0035] The present invention also provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it is used to implement the above-mentioned Unikernel running method based on Kubernetes.
[0036] Compared with the prior art, the present invention has the following excellent effects:
[0037] (1) The running method and device provided by the present invention can connect the Unikernel of the lightweight operating system to Containerd and Kubernetes, so as to make full use of the advantages of the Unikernel and improve the isolation and security of the container.
[0038] (2) The runtime environment in the running method and device provided by the present invention can manage all Unikernels and make them adapt to the architecture of the service network, further improving the efficiency and stability of the container service.
[0039] (3) The running method and device provided by the present invention can optimize the running environment to support the vmfunc communication technology, thereby accelerating the communication efficiency between Unikernels and improving the overall running efficiency. Description of the Drawings
[0040] Figure 1 It is a flowchart of a method for running Unikernel based on Kubernetes provided by the present invention. Detailed Embodiments
[0041] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0042] As Figure 1 shown, the method for running Unikernel based on Kubernetes provided by the present invention includes the following steps:
[0043] (1) Parse the configuration file and create a Unikernel structure to save the status information of the Unikernel;
[0044] (2) Start the daemon process of the Unikernel according to the status information saved in step (1), and then send a pause signal to the daemon process for subsequent recovery;
[0045] (3) After restoring the daemon process of the corresponding Unikernel, start the Unikernel process using the saved status information;
[0046] (4) After the Unikernel process is started, make the daemon process wait for the Unikernel process to exit;
[0047] (5) After the Unikernel process exits, delete the saved status information.
[0048] In a specific embodiment, a CRI runtime named Runu is implemented for Unikraft to implement the above running method. It can handle the life cycle of Unikernels and allow them to be deployed in a Kubernetes environment; Runu can be understood as a tool for managing client runtimes developed in Go, and its main function is to encapsulate QEMU to manage the creation and deletion of Unikernels; in addition, runu implements an IOCTL middleware for managing EPTP information related to Unikernels for Unikernel to use the vmfunc technology.
[0049] The specific running method includes the following steps:
[0050] Step 1: Runu create will parse the configuration file and create a Unikernel structure containing all information, and then save the status information for later use.
[0051] The creation command of Runu includes the id of the custom Unikernel, and the type of the Unikernel will be saved in the configuration file for later use when kvm allocates EPTP.
[0052] At the same time, the configuration file config.json conforms to the oci standard, which includes important information such as the specific startup command, environment variables, file system, mounts, namespaces, etc. of the Unikernel.
[0053] Step 2: Runu will start the Unikernel daemon process according to the status information saved in Step 1. This daemon process is responsible for the startup of the Unikernel and the configuration of various environments, and then sends a pause signal to the daemon process for subsequent recovery.
[0054] Specifically, the daemon process will first use the IOCTL system call according to the type of the Unikernel, and then pass the information to an intermediate kernel module. This kernel module plays a role of transfer. It directly calls the functions in kvm to allocate the EPTP index and returns it to the intermediate module and then to Runu. This index is unique to each Unikernel, so as to ensure that the EPTP index of each Unikernel will not be repeated, thus ensuring the use of vmfunc.
[0055] After obtaining the EPTP index, the daemon process starts to prepare to start the Unikernel. The process includes:
[0056] Prepare the network environment of the Unikernel, and add the process to the network namespace provided by the cni plugin in kubernetes, so that the Unikernel can be accessed and used in kubernetes.
[0057] Prepare the file system environment of the Unikernel, check whether the format in the root directory folder is correct, and process the corresponding mount items.
[0058] Prepare the startup command of the Unikernel. Generally speaking, it will include: the kernel image file of the Unikernel, file mounts, network ports, resource limits, etc.
[0059] After the preparation process, Runu will start the command through cmd and send the kill-19 command, that is, the SIGSTOP command, to the daemon process after the start command to pause the startup of the unikernel. Subsequently, Runu will save the state of the unikernel and also save the process id of the daemon process and the EPTP index corresponding to the unikernel.
[0060] Step 3: Runu start will start the corresponding unikernel according to the provided unikernel id.
[0061] Specifically, Runu will obtain the previously saved state information of the corresponding unikernel according to the id (including the state information saved in Step 1 and Step 2), and restore it to the corresponding structure. After obtaining the structure, it will send the kill-18 command, that is, the SIGCONT command, to the previously saved daemon process corresponding to the unikernel to resume the corresponding unikernel process. In this way, the real unikernel process will start.
[0062] After startup, the unikernel's daemon process will wait for the unikernel process to exit. Whether it is stopped manually or exits by itself, it can trigger the next operation of the daemon process.
[0063] Runu can use the list command to obtain all running unikernels. The specific principle is to traverse the state information of all unikernels. Through the state information, the states of all unikernels can be obtained, and then returned to interfaces such as the terminal or Containerd.
[0064] Step 4: Runu kill will cause the corresponding unikernel to exit gracefully and handle a series of information before and after the process exits.
[0065] Specifically, Runu kill will first parse the semaphore in the command line parameters and send it to the unikernel process through the semaphore. If the unikernel process is exited, then the daemon process corresponding to the unikernel will start the follow-up work, which specifically includes stopping all unikernel-related child processes, sending the SIGCHLD signal indicating that the child process has been stopped to the Containerd-shim process, and handling the logic of unikernel service cancellation.
[0066] The reason for handling Unikernel service deregistration is that if the Unikernel sends a service registration request to the registry through vmfunc when it starts up, then if the Unikernel crashes without sending a deregistration request to the registry in time, it will cause data inconsistency in the service registry. Therefore, at this time, Runu needs to send an HTTP data packet to the service registry, carrying the EPTP index of the Unikernel, so that the registry can deregister the relevant Unikernel services in time.
[0067] Step 5: Runu delete will completely delete the corresponding Unikernel, including status information and other information.
[0068] In this way, through the five steps of Runu, the life cycle of the Unikernel can be completely managed, ensuring the normal use of the vmfunc function, and at the same time having the ability to access Containerd and Kubernetes.
[0069] Through the above running method, the present invention can effectively manage the life cycle of the Unikernel, ensure the normal use of the vmfunc function, and at the same time have the ability to access Containerd and Kubernetes.
[0070] The embodiment of the present invention also provides a Unikernel running device based on Kubernetes, including one or more processors. There is executable code stored in the memory. When the processor executes the executable code, it is used to implement the Unikernel running method based on Kubernetes in the above embodiment. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of any device with data processing ability reading the corresponding computer program instructions in the non-volatile memory into the memory and running. From a hardware level, in addition to the processor, memory, network interface, and non-volatile memory, any device with data processing ability where the device in the embodiment is located usually also includes other hardware according to the actual function of the any device with data processing ability, which will not be elaborated here.
[0071] An embodiment of the present invention further provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the method for running a unikernel based on Kubernetes in the above embodiment is implemented: The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the foregoing embodiments, such as a hard disk or memory. The computer-readable storage medium may also be any device with data processing capabilities, such as a plug-in hard disk, a Smart Media Card (SMC), an SD card, a Flash8 Card, etc. equipped on the device. Further, the computer-readable storage medium may also include both an internal storage unit of any device with data processing capabilities and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or will be output.
[0072] The above are only embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.
Claims
1. A method for running Unikernel based on Kubernetes, characterized in that, The running method includes: (1) Parse the configuration file and create a Unikernel structure to save the status information of the Unikernel; (2) Start the daemon process of the Unikernel according to the status information saved in step (1), and then send a pause signal to the daemon process for subsequent recovery; (3) After recovering the daemon process corresponding to the Unikernel, start the Unikernel process using the saved status information; (4) After the Unikernel process starts, make the daemon process wait for the Unikernel process to exit; (5) After the Unikernel process exits, delete the saved status information; In step (2), after the daemon process starts, the following operations are performed: (2-1) Use the IOCTL system call to obtain the extended page table pointer information of the Unikernel according to the type of the Unikernel; (2-2) Perform environment configuration: prepare the network environment of the Unikernel, prepare the file system environment of the Unikernel, and prepare the startup command of the Unikernel; In step (2-2), the method of the environment configuration includes: (2-2-1) Prepare the network environment of the Unikernel: Add the Unikernel process to the network namespace provided by the API interface of the container network in kubernetes; (2-2-2) Prepare the file system environment of the Unikernel: Check whether the format in the root directory folder is correct and process the corresponding mount items; (2-2-3) Prepare the startup command of the Unikernel: The startup command includes the kernel image file of the Unikernel, file mounts, network ports, and resource limits.
2. The method for running Unikernel based on Kubernetes according to claim 1, wherein In step (1), the configuration file includes the startup command, environment variables, file system, mounts, and namespaces of the Unikernel. The Unikernel structure includes the id of the Unikernel, and the type of the Unikernel is saved in the configuration file.
3. The method for running Unikernel based on Kubernetes according to claim 1, wherein In step (2), after the startup command is prepared, the daemon process receives a command to pause the startup of the Unikernel process, and then saves the status information of the Unikernel, the process id of the daemon process, and the extended page table pointer information corresponding to the Unikernel.
4. The method for running Unikernel based on Kubernetes according to claim 3, wherein In step (3), the method for the daemon process to start the Unikernel process is: Obtain the status information corresponding to the Unikernel according to the id of the Unikernel, restore it to the corresponding structure from the status information, and then send a command to the corresponding daemon process to restore the corresponding Unikernel process. At this time, the real Unikernel process starts; among them, the status information includes the status information saved in steps (1) and (2).
5. The method for running Unikernel based on Kubernetes according to claim 1, wherein In step (4), when the daemon process waits for the Unikernel process to exit, the daemon process saves the status information of all running Unikernels. The specific method is as follows: traverse the status information of all Unikernels, and save the status information of all Unikernels after obtaining it through the status information.
6. The method for running Unikernel based on Kubernetes according to claim 1, wherein In step (4), during the process of the Unikernel process exiting, the following operations need to be performed: stop the subprocesses related to the Unikernel, send a signal indicating that the subprocesses have been stopped to Containerd, and handle the logic of Unikernel service deregistration.
7. A Unikernel running device based on Kubernetes, including a memory and one or more processors. An executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement the Unikernel running method based on Kubernetes according to any one of claims 1-6.
8. A computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it is used to implement the Unikernel running method based on Kubernetes according to any one of claims 1-6.
Citation Information
Patent Citations
Sandbox implementation method and device, equipment and storage medium
CN113297566A
Container security solution method and system based on lightweight virtual machine
CN115113984A
Method and system for realizing simultaneous management of virtual machine and container based on kubernetes
CN115599492A
System, method and apparatus for providing container services
CN109582441A
Storage mounting method and device and electronic equipment
CN114546269A