Application Deployment Isolation Method, System and Medium for Container Cloud Scenarios
By creating different levels of resource pools and configuring security policies in the kubernetes container cloud scenario, the problem of application deployment cannot be automated and quarantined is solved, and the secure automatic deployment of applications and multi-tenant resource isolation is achieved.
Patent Information
- Application Number
- CN202411766573.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-12-04
AI Technical Summary
The existing kubernetes container cloud scenarios cannot automatically deploy applications, and cannot restrict applications from being deployed on nodes that are securely controlled by different organizations, which cannot physically isolate them from the network.
In the container cloud scenario, create platform shared resource pools, organization shared resource pools, and organization-specific security domain pools, and configure security levels and preset access security policies for each resource pool, automatic deployment isolation of applications is achieved. The specific steps include obtaining the security level of the application and determining whether there is a matching resource pool. If it exists, it will be deployed on the node of the resource pool, otherwise it will return the deployment failure information.
The automated deployment of applications is realized, ensuring that applications can only be deployed in resource pools that meet their security levels, improving security controls for server resource isolation and application isolation in multi-tenant scenarios, and avoiding unauthorized application access or deployment to sensitive nodes.
Smart Images

Figure CN119254539B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of application deployment isolation, and particularly to an application deployment isolation method, system and medium applied to the container cloud scenario. Background Art
[0002] Kubernetes is the industry standard for container cloud orchestration. Building a private container cloud around Kubernetes, constructing enterprise applications and carrying out cloud transformation can greatly improve the efficiency of automated management and delivery of applications.
[0003] The existing Kubernetes container cloud scenario provides an isolation mechanism based on namespaces. A namespace is an abstract mechanism used to isolate resources in a cluster. By placing different resources in different namespaces, limited multi-tenant isolation is achieved. When deploying an application, the administrator needs to match and deploy to a suitable node by using a Label label or specifying a node name. The Label label can be used to identify node characteristics, such as resource quotas, environments, etc., so that the application can select a node that meets the requirements for deployment.
[0004] However, since different organizational tenants under the private cloud manage their own node resources respectively, when deploying an application, the administrator needs to deploy the application manually. In addition, since the configuration is done through Label labels or specifying node names, when there is no corresponding Label label or specified node name in the current organization, it is impossible to restrict the application from being deployed on nodes securely controlled by different organizations, and physical and network isolation cannot be achieved.
[0005] Therefore, there is an urgent need for an application deployment isolation method, system and medium applied to the container cloud scenario to solve the problems that the existing Kubernetes container cloud scenario cannot automatically deploy applications, cannot restrict the application from being deployed on nodes securely controlled by different organizations, and thus cannot achieve physical and network isolation. Summary of the Invention
[0006] In view of the above deficiencies of the prior art, this application provides an application deployment isolation method, system and medium applied to the container cloud scenario to solve the problems that the existing Kubernetes container cloud scenario cannot automatically deploy applications, cannot restrict the application from being deployed on nodes securely controlled by different organizations, and thus cannot achieve physical and network isolation.
[0007] In a first aspect, this application provides an application deployment isolation method applied to the container cloud scenario. The method includes:
[0008] In the container cloud scenario, create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and an organization-wide security domain dedicated pool. Integrate the resource pool as a custom resource into the container cloud storage system, add node resources to the resource pool, and configure the security level and preset access security policy for each resource pool. When any organization A needs to deploy an application, obtain the security level of the application. Determine whether there is an organization-wide security domain dedicated pool with the same security level as the application in organization A. If there is a security domain dedicated pool with the same security level as the application, deploy the application on the node corresponding to the security domain dedicated pool. If there is no node in the security domain dedicated pool that can deploy the application, return application deployment failure information. ; When there is no dedicated pool for the security domain within the organization with the same security level as the application, determine whether organization A has an organizational shared resource pool with the same security level as the application; when there is an organizational shared resource pool with the same security level as the application, deploy the application on a node with the same security level; when there is no organizational shared resource pool with the same security level as the application or there is no node in the organizational shared resource pool that can deploy the application, determine whether there is a node with the same security level as the application in the platform shared resource pool; when there is a node with the same security level as the application and the node meets the preset application deployment conditions, deploy the application on the node with the same security level; otherwise, return application deployment failure information.
[0009] The application deployment isolation method provided in the embodiment of the present application creates resource pools of different levels (platform shared resource pool, organization shared resource pool and security domain dedicated pool within the organization) and configures corresponding security levels and preset access security policies. This method ensures that the application can only be deployed in a resource pool that meets its security level. At the same time, different preset access security policies can be configured for different resource pools, thereby controlling the access to nodes in each resource pool. This helps prevent unauthorized application access or deployment to sensitive nodes. In addition, the traditional kubernetes container cloud scenario cannot automatically deploy applications and cannot restrict application deployment on nodes that are securely controlled by different organizations. However, this application uses an automated process to automatically deploy applications on nodes at corresponding security levels according to the security level and resource pool of the application. When the application security level is relatively special, it can be deployed in a security domain dedicated pool at a specific security level. When there is no node in the security domain dedicated pool at a specific security level, the deployment is stopped, avoiding the problem of being unable to restrict application deployment on nodes that are securely controlled by different organizations. In addition, the present application involves clear security level and resource pool division, which reduces deployment failures caused by resource competition or security policy conflicts. When a node that meets the application security level cannot be found, the system returns a deployment failure message, avoiding potential errors and conflicts.
[0010] In an implementation manner of the present application, the resource pool is at least divided into: an unallocated platform shared resource pool, a platform shared resource pool, an unallocated organizational resource pool, an organizational shared resource pool, and a dedicated pool for security domains within an organization; adding node resources to the resource pool specifically includes:
[0011] Adding newly added node resources to the unallocated platform shared resource pool; based on external triggers, determining the organizational or platform shared resource pool corresponding to the newly added node resources; wherein, there is a corresponding relationship between an organization and its unallocated organizational resource pool, organizational shared resource pool, and dedicated pool for security domains within the organization, and the security levels configured for the organizational shared resource pool and the dedicated pool for security domains within the same organization are different, and the same security level corresponds to only one platform shared resource pool; when the newly added node resources correspond to an organization, adding the newly added node resources to the unallocated organizational resource pool corresponding to the organization; based on external triggers, determining the organizational shared resource pool or the dedicated pool for security domains within the organization corresponding to the newly added node resources in the unallocated organizational resource pool; wherein, an organization corresponds to an organizational shared resource pool and a dedicated pool for security domains within the organization, and the security levels of the organizational shared resource pool and the dedicated pool for security domains within the organization are different.
[0012] The application deployment isolation method provided by the embodiments of the present application ensures the security and isolation of resources by creating exclusive resource pools (unallocated organizational resource pool, organizational shared resource pool, and dedicated pool for security domains within an organization) for different organizations and configuring different security levels.
[0013] In an implementation manner of the present application, the method further includes: when the node resources in the organizational shared resource pool or the dedicated pool for security domains within an organization are released, they can be returned to the unallocated organizational resource pool corresponding to the current organization; when the node resources in the unallocated organizational resource pool or the platform shared resource pool are released, they can be returned to the unallocated platform shared resource pool.
[0014] In an implementation manner of the present application, when there is a dedicated pool for security domains with the same security level as the application, deploying the application on the nodes corresponding to the dedicated pool for security domains specifically includes: reading the processing capabilities, memory sizes, and network bandwidths of the nodes in the dedicated pool for security domains, and deploying the application on any node whose processing capabilities, memory sizes, and network bandwidths meet the preset requirements.
[0015] In an implementation manner of the present application, the situation where there are no nodes in the dedicated pool for security domains that can deploy the application specifically includes:
[0016] All node resources of the nodes in the security domain dedicated pool are released, and there are no nodes in the security domain dedicated pool; the processing capabilities, memory sizes, and network bandwidths of all nodes in the security domain dedicated pool do not meet the preset application deployment conditions; there are no nodes in the organization's shared resource pool that can deploy the application, specifically including: all node resources of the nodes in the organization's shared resource pool are released, and there are no nodes in the organization's shared resource pool; the processing capabilities, memory sizes, and network bandwidths of all nodes in the organization's shared resource pool do not meet the preset application deployment conditions.
[0017] In an implementation manner of the present application, the preset access security policy is any one or more security policies in Kubernetes; the security levels include at least: internal public, several classified levels, and the second classified level, and the security level of any resource pool cannot be modified.
[0018] In a second aspect, the present application provides an application deployment isolation system applied to a container cloud scenario. The system includes:
[0019] A resource pool creation module, configured to create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and an in-organization security domain dedicated pool in a container cloud scenario, integrate the resource pools as custom resources into the storage system of the container cloud, add node resources to the resource pools, and configure security levels and preset access security policies for each resource pool; an application deployment module, configured to, when any organization A needs to deploy an application, obtain the security level of the application; determine whether there is an in-organization security domain dedicated pool in organization A with the same security level as the application. When there is a security domain dedicated pool with the same security level as the application, deploy the application on the nodes corresponding to the security domain dedicated pool. When there are no nodes in the security domain dedicated pool that can deploy the application, return an application deployment failure message; when there is no in-organization security domain dedicated pool in organization A with the same security level as the application, determine whether there is an organization shared resource pool in organization A with the same security level as the application; when there is an organization shared resource pool with the same security level as the application, deploy the application on the nodes with the same security level; when there is no organization shared resource pool with the same security level as the application or there are no nodes in the organization shared resource pool that can deploy the application, determine whether there are nodes in the platform shared resource pool with the same security level as the application; when there are nodes with the same security level as the application and the nodes meet the preset application deployment conditions, deploy the application on the nodes with the same security level; otherwise, return an application deployment failure message.
[0020] In an implementation manner of the present application, the resource pool creation module includes a node configuration unit, which is used to add newly added node resources to the unallocated shared resource pool of the platform; based on an external trigger, determine the organization or platform shared resource pool corresponding to the newly added node resources; wherein, there is a corresponding relationship between the organization and the organization's unallocated resource pool, the organization's shared resource pool, and the dedicated pool of the security domain within the organization. The security levels configured for the organization's shared resource pool and the dedicated pool of the security domain within the same organization are different, and only one platform shared resource pool corresponds to the same security level; when the newly added node resources correspond to an organization, add the newly added node resources to the organization's unallocated resource pool corresponding to the organization; based on an external trigger, determine the organization's shared resource pool or the dedicated pool of the security domain within the organization corresponding to the newly added node resources in the organization's unallocated resource pool; wherein, the organization corresponds to the organization's shared resource pool and the dedicated pool of the security domain within the organization, and the security levels of the organization's shared resource pool and the dedicated pool of the security domain within the organization are different.
[0021] In an implementation manner of the present application, the resource pool creation module includes a node release unit. When the node resources in the organization's shared resource pool or the dedicated pool of the security domain within the organization are released, it can return to the organization's unallocated resource pool corresponding to the current organization; when the node resources in the organization's unallocated resource pool or the platform shared resource pool are released, it can return to the unallocated shared resource pool of the platform.
[0022] In a third aspect, the present application provides a non-volatile computer storage medium, on which computer instructions are stored. When the computer instructions are executed, they implement an application deployment isolation method for a container cloud scenario as described in any one of the above.
[0023] Those skilled in the art can understand that the present application has at least the following beneficial effects:
[0024] By creating resource pools at different levels (platform shared resource pool, organization shared resource pool, and dedicated pool for security domains within the organization) and configuring corresponding security levels and preset access security policies, this method ensures that applications can only be deployed in resource pools that match their security levels. At the same time, different preset access security policies can be configured for different resource pools, thereby controlling the access to nodes within each resource pool. This helps prevent unauthorized application access or deployment to sensitive nodes. Additionally, in traditional kubernetes container cloud scenarios, it is impossible to automatically deploy applications and restrict the deployment of applications to nodes under the security control of different organizations. However, in this application, through an automated process, based on the security level of the application and the resource pool, the application is automatically deployed on nodes corresponding to the appropriate security level. When the security level of the application is relatively special, it can be deployed in the dedicated pool for security domains with a specific security level. When there are no nodes in the dedicated pool for security domains with a specific security level, the deployment is stopped, avoiding the problem of being unable to restrict the deployment of applications to nodes under the security control of different organizations. That is, the application deployment involved in this application is only installed on the nodes corresponding to the resource pool of the organization and the platform shared resource pool, avoiding the problem of being unable to restrict the deployment of applications to nodes under the security control of different organizations, and improving the security control of server resource isolation and application isolation in a multi-tenant scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The following describes some embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0026] Figure 1 is a flowchart of an application deployment isolation method applied to a container cloud scenario provided by an embodiment of the present application.
[0027] Figure 2 is a schematic diagram of the internal structure of an application deployment isolation system applied to a container cloud scenario provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] Those skilled in the art should understand that the embodiments described below are only the preferred embodiments of the present disclosure, and do not mean that the present disclosure can only be implemented through these preferred embodiments. These preferred embodiments are only used to explain the technical principles of the present disclosure and are not used to limit the protection scope of the present disclosure. Based on the preferred embodiments provided by the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts should still fall within the protection scope of the present disclosure.
[0029] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0030] The technical solutions proposed in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0031] The embodiment provides an application deployment isolation method applied to the container cloud scenario, as Figure 1 shown, the method provided by the embodiment of the present application mainly includes the following steps:
[0032] Step 110: Create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and an organization-internal security domain dedicated pool in the container cloud scenario, integrate the resource pools as custom resources into the storage system of the container cloud, add node resources to the resource pools, and configure security levels and preset access security policies for each resource pool.
[0033] It should be noted that the specific security levels and preset access security policies corresponding to the resource pools can be preset by those skilled in the art according to the planning of the resource pools and the allocation needs of the nodes. In addition, the preset access security policies are security policies in Kubernetes, such as configurations of Ingress, Egress, firewall rules, etc., and are used for security control to restrict internal and external access of applications. In addition, the preset access security policies can also include that if multiple applications of an organization are deployed on nodes with the same security level, they can communicate with each other. Applications on nodes across organizations and across security classification levels are not allowed to communicate with each other. In addition, the number of organization shared resource pools and organization-internal security domain dedicated pools within each organization is not the same, and can be set by those skilled in the art according to actual needs.
[0034] In some embodiments, the resource pools can be classified into the following categories: platform unallocated shared resource pool, platform shared resource pool, organization unallocated resource pool, organization shared resource pool, and organization-internal security domain dedicated pool.
[0035] Each organization's organization shared resource pool and organization-internal security domain dedicated pool need to be configured with a security level to implement access restriction permissions. The security levels can be defined as: internal public, top secret, secret, confidential, etc. The security levels cannot be modified after being bound.
[0036] Specifically, for the platform's unallocated resource pool: When adding a new server to the container cloud cluster, it first enters the unallocated state and is managed by the unallocated resource pool. After that, the system administrator can reallocate the servers in the pool to different organizations and automatically allocate them to the unallocated resource pools of the organizations.
[0037] Platform shared resource pool: Multiple platform shared resource pools with different security levels can be created. Each pool is bound to an unmodifiable security level.
[0038] Organization's unallocated resource pool: The resource pool that can be managed under an organization. Node resources can be allocated to the shared resource pools of each organization within the organization or the dedicated pools for security domains within the organization.
[0039] Organization shared resource pool: Multiple organization shared resource pools with different security levels can be created as needed. Each organization shared resource pool is bound to an unmodifiable security level.
[0040] Dedicated pool for security domain: Multiple dedicated pools for security domains with different security levels can be created as needed. It is a resource pool created for a specific confidentiality level. This dedicated pool for the security domain cannot be shared within the organization. Nodes entering the dedicated pool will obtain the highest security guarantee. For example, create a dedicated pool for the confidential security domain. Deploy applications that require confidential level control in this dedicated pool and restrict the deployment of applications with other confidentiality level controls on the lower nodes. When deploying applications, if there is a corresponding dedicated pool, first search for available nodes in the dedicated pool. An organization can only define one dedicated pool for a security domain for one security level. It is not allowed to define dedicated pools for multiple confidentiality levels, and shared access to dedicated node resources is prohibited.
[0041] Based on the above description, adding node resources to the resource pool can specifically be:
[0042] Adding new node resources to the unallocated shared resource pool of the platform; Based on external triggers, determining the organization or platform shared resource pool corresponding to the new node resources; Among them, there is a corresponding relationship between the organization and the organization's unallocated resource pool, organization shared resource pool, and dedicated pool for the security domain within the organization. The security levels configured for the organization shared resource pool and the dedicated pool for the security domain within the same organization are different, and the same security level only corresponds to one platform shared resource pool; When the new node resources correspond to an organization, add the new node resources to the organization's corresponding unallocated resource pool; Based on external triggers, determining the organization shared resource pool or dedicated pool for the security domain within the organization corresponding to the new node resources in the organization's unallocated resource pool; Among them, the organization corresponds to the organization shared resource pool and the dedicated pool for the security domain within the organization, and the security levels of the organization shared resource pool and the dedicated pool for the security domain within the organization are different.
[0043] In addition, the nodes in the resource pool are allowed to be released from the pool and can be returned to the unallocated resource pool at the upper level. After operations such as resetting and initializing the nodes, they can be reallocated to resource pools with different security levels, thus implementing mechanisms such as node cleaning and reallocation.
[0044] As an example, when the node resources in the organization's shared resource pool or the dedicated pool of the security domain within the organization are released, the node resources can return to the organization's unallocated resource pool corresponding to the current organization; when the node resources in the organization's unallocated resource pool or the platform's shared resource pool are released, the node resources can return to the platform's unallocated shared resource pool.
[0045] In addition, the overall implementation solution of the resource pool can be as follows:
[0046] Abstract resource pool objects define various resource pool structures at the platform and organization levels. The resource pools created by the system administrator or the platform administrator are integrated into the storage system of the container cloud in the form of custom resources (CRD). And a controllermanager component is provided to monitor operations such as the creation / modification / deletion of user resource pools. Then, it notifies the Reconciler component to perform the management of node resources, create the corresponding resource pool resources, and update the association relationship between the resource pool and the nodes. At the same time, network and security control policies are added to the nodes in the resource pool to restrict network communication between nodes. If multiple applications of an organization are deployed on nodes with the same security level, they can communicate with each other. Applications on nodes across different organizations and different security levels are not allowed to communicate with each other. Thus, a resource pool security mechanism based on security levels is implemented to provide complete isolation for the deployment of applications and the communication between applications.
[0047] Step 120: When any organization A needs to deploy an application, obtain the security level of the application; determine whether there is a dedicated pool for the security domain within the organization with the same security level as the application in organization A. When there is a dedicated pool for the security domain with the same security level as the application, deploy the application on the nodes corresponding to the dedicated pool for the security domain. When there are no nodes in the dedicated pool for the security domain that can deploy the application, return an application deployment failure message.
[0048] It should be noted that this step can be implemented by the container cloud scheduler (kube-scheduler). The container cloud scheduler is used to obtain the security level of the application and first check whether there is a dedicated pool for the security domain with the corresponding security level in the dedicated pool for the security domain (the existence of a dedicated pool for the security domain with the corresponding security level indicates that the application has higher deployment restrictions and can only be deployed on the nodes of the dedicated pool for the security domain).
[0049] In addition, the specific solution for deploying the application on a node in the dedicated pool for the security domain can be as follows:
[0050] Read the processing capacity, memory size, and network bandwidth of the nodes in the dedicated pool of the security domain, and deploy the application on any node whose processing capacity, memory size, and network bandwidth meet the preset requirements.
[0051] Step 130: When there is no dedicated pool of the security domain within the organization with the same security level as the application, determine whether there is an organization shared resource pool within Organization A with the same security level as the application; when there is an organization shared resource pool with the same security level as the application, deploy the application on the nodes with the same security level; when there is no organization shared resource pool with the same security level as the application or there are no nodes in the organization shared resource pool that can deploy the application, determine whether there are nodes with the same security level as the application in the platform shared resource pool; when there are nodes with the same security level as the application and the nodes meet the preset application deployment conditions, deploy the application on the nodes with the same security level; otherwise, return an application deployment failure message.
[0052] In some embodiments, there are no nodes in the dedicated pool of the security domain that can deploy the application. Specifically, it can be:
[0053] The node resources of the nodes in the dedicated pool of the security domain are all released, and there are no nodes in the dedicated pool of the security domain; the processing capacity, memory size, and network bandwidth of all the nodes in the dedicated pool of the security domain do not meet the preset application deployment conditions.
[0054] In some embodiments, there are no nodes in the organization shared resource pool that can deploy the application. Specifically, it can be:
[0055] The node resources of the nodes in the organization shared resource pool are all released, and there are no nodes in the organization shared resource pool; the processing capacity, memory size, and network bandwidth of all the nodes in the organization shared resource pool do not meet the preset application deployment conditions.
[0056] Based on the previous description, it can be known that in this embodiment, by defining the planning, implementation of the resource pool, and the security scheduling mechanism during application deployment, the server resources under different tenants in the container cloud are managed uniformly and efficiently. And it ensures the security scheduling of application deployment, improves the isolation of server resources in the multi-tenant scenario, and the security control of application isolation.
[0057] In addition, this application Figure 2 This is an application deployment isolation system applied to the container cloud scenario provided by the embodiments of this application. As Figure 2 shown, the system provided by the embodiments of this application mainly includes:
[0058] The resource pool creation module 210 is used to create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and a dedicated pool for security domains within the organization in the container cloud scenario, integrate the resource pool as a custom resource into the storage system of the container cloud, add node resources to the resource pool, and configure security levels and preset access security policies for each resource pool.
[0059] The resource pool creation module 210 includes a node configuration unit, which is used to add new node resources to the platform unallocated shared resource pool; based on external triggers, determine the organization or platform shared resource pool corresponding to the new node resources; among them, there is a corresponding relationship between the organization and the organization unallocated resource pool, the organization shared resource pool, and the dedicated pool for security domains within the organization. The security levels configured for the organization shared resource pool and the dedicated pool for security domains within the same organization are different, and the same security level only corresponds to one platform shared resource pool; when the new node resources correspond to an organization, add the new node resources to the organization unallocated resource pool corresponding to the organization; based on external triggers, determine the organization shared resource pool or the dedicated pool for security domains within the organization corresponding to the new node resources in the organization unallocated resource pool; among them, the organization corresponds to the organization shared resource pool and the dedicated pool for security domains within the organization, and the security levels of the organization shared resource pool and the dedicated pool for security domains within the organization are different.
[0060] The resource pool creation module 210 includes a node release unit, which can return the organization unallocated resource pool corresponding to the current organization when the node resources in the organization shared resource pool or the dedicated pool for security domains within the organization are released; when the node resources in the organization unallocated resource pool or the platform shared resource pool are released, it can return the platform unallocated shared resource pool.
[0061] The application deployment module 220 is used to obtain the security level of the application when any organization A needs to deploy an application; determine whether there is a dedicated pool for security domains within organization A with the same security level as the application. When there is a dedicated pool for security domains with the same security level as the application, deploy the application on the nodes corresponding to the dedicated pool for security domains. When there are no nodes in the dedicated pool for security domains that can deploy the application, return an application deployment failure message; when there is no dedicated pool for security domains within organization A with the same security level as the application, determine whether there is an organization shared resource pool within organization A with the same security level as the application; when there is an organization shared resource pool with the same security level as the application, deploy the application on the nodes with the same security level; when there is no organization shared resource pool with the same security level as the application or there are no nodes in the organization shared resource pool that can deploy the application, determine whether there are nodes with the same security level as the application in the platform shared resource pool; when there are nodes with the same security level as the application and the nodes meet the preset application deployment conditions, deploy the application on the nodes with the same security level; otherwise, return an application deployment failure message.
[0062] In addition, the embodiments of the present application further provide a non-volatile computer storage medium, on which executable instructions are stored, and when the executable instructions are executed, an application deployment isolation method applied to a container cloud scenario as described above is implemented.
[0063] So far, the technical solutions of the present disclosure have been described in combination with multiple foregoing embodiments. However, those skilled in the art can easily understand that the protection scope of the present disclosure is not limited to these specific embodiments. Without departing from the technical principle of the present disclosure, those skilled in the art can split and combine the technical solutions in the foregoing embodiments, and can also make equivalent changes or replacements to relevant technical features. Any changes, equivalent replacements, improvements, etc. made within the technical concept and / or technical principle of the present disclosure will fall within the protection scope of the present disclosure.
Claims
1. An application deployment isolation method applied to a container cloud scenario, characterized in that: The method comprises: In the container cloud scenario, create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and a dedicated pool for the security domain within the organization. Integrate the resource pool as a custom resource into the storage system of the container cloud, add node resources to the resource pool, and configure the security level and preset access security policy for each resource pool. Among them, the platform shared resource pool can create multiple platform shared resource pools with different security levels, and each platform shared resource pool is bound to an unmodifiable security level; the organization unallocated resource pool: a resource pool that can be managed under the organization, which can allocate node resources to each organization shared resource pool or security domain dedicated pool within the organization; the organization shared resource pool can create multiple organization shared resource pools with different security levels on demand, and each organization shared resource pool is bound to an unmodifiable security level; the security domain dedicated pool can create multiple security domain dedicated pools with different security levels on demand, and the security domain dedicated pool cannot be shared within the organization; nodes entering the security domain dedicated pool will receive the highest security guarantee; applications that require confidentiality level control will be deployed in the corresponding security domain dedicated pool, and other confidentiality level controlled applications will be restricted from being deployed on the nodes below; when deploying an application, if there is a corresponding dedicated pool, it will be preferred to find available nodes from the security domain dedicated pool; an organization can only define one security domain dedicated pool for a security level, and shared access to dedicated node resources is prohibited; When any organization A needs to deploy an application, obtain the security level of the application; determine whether there is an intra-organization security domain dedicated pool with the same security level as the application in organization A. When there is a security domain dedicated pool with the same security level as the application, deploy the application on the node corresponding to the security domain dedicated pool. When there is no node in the security domain dedicated pool that can deploy the application, specifically including: the node resources of the nodes in the security domain dedicated pool are all released, and there are no nodes in the security domain dedicated pool; the processing power, memory size, and network bandwidth of all nodes in the security domain dedicated pool do not meet the preset application deployment conditions, and the application deployment failure information is returned; When there is no dedicated pool for the security domain within the organization with the same security level as the application, determine whether organization A has an organizational shared resource pool with the same security level as the application; when there is an organizational shared resource pool with the same security level as the application, deploy the application on a node with the same security level; when there is no organizational shared resource pool with the same security level as the application or there is no node in the organizational shared resource pool that can deploy the application, determine whether there is a node with the same security level as the application in the platform shared resource pool; when there is a node with the same security level as the application and the node meets the preset application deployment conditions, deploy the application on the node with the same security level; otherwise, return application deployment failure information.
2. The application deployment isolation method applied to the container cloud scenario according to claim 1 is characterized in that: The resource pool is divided into at least: platform unallocated shared resource pool, platform shared resource pool, organization unallocated resource pool, organization shared resource pool, and dedicated pool for security domain within the organization; Add node resources to the resource pool, including: Add new node resources to the platform's unallocated shared resource pool; Based on external triggers, determine the organization or platform shared resource pool corresponding to the newly added node resources; among them, there is a corresponding relationship between the organization and the organization's unallocated resource pool, the organization's shared resource pool, and the organization's internal security domain dedicated pool. The security levels of the organization's shared resource pool and the organization's internal security domain dedicated pool under the same organization are different; When the newly added node resources correspond to an organization, the newly added node resources are added to the organization's unallocated resource pool corresponding to the organization; Based on external triggers, determine the organization shared resource pool or the organization security domain dedicated pool corresponding to the newly added node resources in the organization's unallocated resource pool; among them, the organization corresponds to the organization shared resource pool and the organization security domain dedicated pool, and the security levels of the organization shared resource pool and the organization security domain dedicated pool are different.
3. The application deployment isolation method applied to the container cloud scenario according to claim 2 is characterized in that: The method further comprises: When the node resources in the organization's shared resource pool or the organization's internal security domain dedicated pool are released, they can be returned to the organization's unallocated resource pool corresponding to the current organization; When node resources in the organization's unallocated resource pool or the platform's shared resource pool are released, they can be returned to the platform's unallocated shared resource pool.
4. The application deployment isolation method applied to the container cloud scenario according to claim 1 is characterized in that: When there is a security domain dedicated pool with the same security level as the application, the application is deployed on the node corresponding to the security domain dedicated pool, including: Read the processing power, memory size, and network bandwidth of the nodes in the security domain dedicated pool, and deploy the application on any node that meets the preset requirements of processing power, memory size, and network bandwidth symbols.
5. The application deployment isolation method applied to the container cloud scenario according to claim 1 is characterized in that: There are no nodes in the organization's shared resource pool that can deploy applications. Specifically: All node resources of nodes in the organization's shared resource pool are released, and there are no nodes in the organization's shared resource pool; The processing power, memory size, and network bandwidth of all nodes in the organization's shared resource pool do not meet the preset application deployment conditions.
6. The application deployment isolation method applied to the container cloud scenario according to claim 1 is characterized in that: The preset access security policy is any one or more security policies in Kubernetes; The security levels include at least: internally disclosed and several confidentiality levels, and the security level of any resource pool cannot be modified.
7. An application deployment isolation system applied to a container cloud scenario, characterized in that: The system comprises: The resource pool creation module is used to create a platform shared resource pool, an organization shared resource pool corresponding to each organization, and a dedicated pool for the security domain within the organization in the container cloud scenario, integrate the resource pool as a custom resource into the storage system of the container cloud, add node resources to the resource pool, and configure the security level and preset access security policy for each resource pool; Among them, the platform shared resource pool can create multiple platform shared resource pools with different security levels, and each platform shared resource pool is bound to an unmodifiable security level; the organization unallocated resource pool: a resource pool that can be managed under the organization, which can allocate node resources to each organization shared resource pool or security domain dedicated pool within the organization; the organization shared resource pool can create multiple organization shared resource pools with different security levels on demand, and each organization shared resource pool is bound to an unmodifiable security level; the security domain dedicated pool can create multiple security domain dedicated pools with different security levels on demand, and the security domain dedicated pool cannot be shared within the organization; nodes entering the security domain dedicated pool will receive the highest security guarantee; applications that require confidentiality level control will be deployed in the corresponding security domain dedicated pool, and other confidentiality level controlled applications will be restricted from being deployed on the nodes below; when deploying an application, if there is a corresponding dedicated pool, it will be preferred to find available nodes from the security domain dedicated pool; an organization can only define one security domain dedicated pool for a security level, and shared access to dedicated node resources is prohibited; The application deployment module is used to obtain the security level of the application when any organization A needs to deploy the application; determine whether there is a dedicated security domain pool in the organization with the same security level as the application. When there is a dedicated security domain pool with the same security level as the application, the application is deployed on the node corresponding to the dedicated security domain pool. When there is no node in the dedicated security domain pool that can deploy the application, the specific conditions include: the node resources of the nodes in the dedicated security domain pool are all released, and there are no nodes in the dedicated security domain pool; the processing power, memory size, and network bandwidth of all nodes in the dedicated security domain pool do not meet the preset application deployment conditions; return application deployment failure information; when there is no node corresponding to the application When there is an organization-wide security domain dedicated pool with the same security level as the application, determine whether organization A has an organization-wide shared resource pool with the same security level as the application; when there is an organization-wide shared resource pool with the same security level as the application, deploy the application on a node with the same security level; when there is no organization-wide shared resource pool with the same security level as the application or there is no node in the organization-wide shared resource pool that can deploy the application, determine whether there is a node with the same security level as the application in the platform shared resource pool; when there is a node with the same security level as the application and the node meets the preset application deployment conditions, deploy the application on the node with the same security level; otherwise, return application deployment failure information.
8. The application deployment isolation system applied to the container cloud scenario according to claim 7 is characterized in that: The resource pool creation module includes a node configuration unit, Used to add new node resources to the platform's unallocated shared resource pool; Based on external triggers, determine the organization or platform shared resource pool corresponding to the newly added node resources; among them, there is a corresponding relationship between the organization and the organization's unallocated resource pool, the organization's shared resource pool, and the organization's internal security domain dedicated pool. The security levels of the organization's shared resource pool and the organization's internal security domain dedicated pool under the same organization are different; When the newly added node resources correspond to an organization, the newly added node resources are added to the organization's unallocated resource pool corresponding to the organization; Based on external triggers, determine the organization shared resource pool or the organization security domain dedicated pool corresponding to the newly added node resources in the organization's unallocated resource pool; among them, the organization corresponds to the organization shared resource pool and the organization security domain dedicated pool, and the security levels of the organization shared resource pool and the organization security domain dedicated pool are different.
9. The application deployment isolation system applied to the container cloud scenario according to claim 7 is characterized in that: The resource pool creation module includes a node release unit, When the node resources in the organization's shared resource pool or the organization's internal security domain dedicated pool are released, they can be returned to the organization's unallocated resource pool corresponding to the current organization; When node resources in the organization's unallocated resource pool or the platform's shared resource pool are released, they can be returned to the platform's unallocated shared resource pool.
10. A non-volatile computer storage medium, characterized in that: Computer instructions are stored thereon, and when the computer instructions are executed, the application deployment isolation method applied to the container cloud scenario as described in any one of claims 1-6 is implemented.
Citation Information
Patent Citations
Container arranging and scheduling method and flow control processing method
CN119071016A