Container-based Policy Orchestration Response Method, System, and Computer Storage Medium
Through the container-based policy orchestration response method, dynamically adjusting the container resource configuration, the problem of insufficient comprehensive and accurate response strategies in the existing technology is solved, and the response speed and efficiency of network security incidents are improved.
Patent Information
- Application Number
- CN202411570459.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-11-06
AI Technical Summary
Existing cybersecurity event automation technologies rely on preset rules and patterns, lack flexibility and accuracy, resulting in insufficient comprehensive and accurate response strategies. Traditional methods may lead to business interruption and extended recovery time when facing cybersecurity threats.
Provide a container-based policy orchestration response method, build container images through the container engine, obtain the container load parameter resource usage data, divide resource usage sequences, analyze local feature vectors and dynamic feature values, determine resource adjustment coefficients, and perform resource configuration adjustments to dynamically optimize container resource allocation.
By dynamically adjusting resource configuration and taking into account the local change trends and fluctuations of container load parameters, the flexibility and accuracy of container resource allocation are improved, and the time and risk of network security incident response are reduced.
Smart Images

Figure CN119440733B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of container orchestration, and specifically relates to a policy orchestration response method, system, and computer storage medium based on containers. Background Art
[0002] In network security incidents, the research and application of automated response technologies are particularly important. Most existing network security incident automated technologies rely on preset rules and patterns, which lack flexibility and accuracy, resulting in response strategies that are not comprehensive and accurate enough. Traditional response methods usually refer to the means and strategies adopted to deal with network security threats in an environment without using containerization and cloud-native architectures. These methods mainly rely on traditional IT infrastructures, such as physical servers, virtual machines, network devices, etc. If attacked, it may be necessary to isolate, repair, or rebuild the entire server or virtual machine, which will lead to greater business interruptions and longer recovery times.
[0003] As a lightweight and independent running environment, containers can ensure that application programs run consistently in any environment. However, when container orchestration tools allocate resources, it is a single-threshold resource configuration that does not consider the dynamic changes in the resource requirements of containers. When resource conflicts occur, low-priority containers will be evicted to ensure the normal supply of resources for high-priority containers, but it is impossible to avoid resource conflict problems among containers with the same priority. Summary of the Invention
[0004] To solve the above technical problems, a policy orchestration response method, system, and computer storage medium based on containers are provided to solve the existing problems.
[0005] The solution of this application to solve the technical problems is to provide a policy orchestration response method, system, and computer storage medium based on containers, including the following steps:
[0006] In the first aspect, an embodiment of this application provides a policy orchestration response method based on containers, and this method includes the following steps:
[0007] Build a container image through a container engine; obtain the resource usage data of each load parameter of each container with the same priority on the nodes in the cluster, and form a resource usage sequence of each load parameter, where the load parameters include: CPU usage rate, memory usage rate, and network bandwidth usage.
[0008] Divide the resource usage sequence into multiple subsequences; analyze the central tendency of the element changes within each subsequence of the resource usage sequence, as well as the fluctuation of the elements within the subsequence, to obtain the local feature vectors of each subsequence; determine the dynamic eigenvalue of each subsequence within the resource usage sequence of each load parameter of each container under the same priority according to the similarity of the changes of the local feature vectors between different subsequences within the resource usage sequence.
[0009] According to the distance relationship of all the dynamic eigenvalues between different load parameters of each container, and the difference in the number of elements within all the subsequences, respectively determine the first relative difference and the second relative difference between each load parameter of each container and the remaining load parameters under the same priority; based on the first relative difference and the second relative difference, determine the relative dynamic difference of each load parameter of each container under the same priority.
[0010] Determine the resource adjustment coefficient of each container under the same priority according to the similarity of all the relative dynamic differences between each container and the remaining containers under the same priority; based on the resource adjustment coefficient, adjust the resource configuration of the containers under the same priority.
[0011] Based on the container image and the resource allocation strategy of the resource configuration adjustment, deploy and monitor the containers through the container orchestration tool.
[0012] Preferably, the obtaining of the local feature vectors of each subsequence includes:
[0013] Calculate the trend statistic and the coefficient of variation of each subsequence within the resource usage sequence.
[0014] Combine the trend statistic and the coefficient of variation to form the local feature vector of each subsequence.
[0015] Preferably, the dynamic eigenvalue of each subsequence within the resource usage sequence of each load parameter of each container under the same priority is the mean value of the dot products of the local feature vectors of each subsequence within the resource usage sequence and all the other subsequences.
[0016] Preferably, the determination of the first relative difference between each load parameter of each container and the remaining load parameters under the same priority includes:
[0017] Form the dynamic eigenvalue sequence by the dynamic eigenvalues of all the subsequences within the resource usage sequence.
[0018] Take the distance of the dynamic eigenvalue sequence between each load parameter of each container and the remaining load parameters under the same priority as the first relative difference between each load parameter of each container and the remaining load parameters under the same priority.
[0019] Preferably, the method for obtaining the second relative difference is as follows:
[0020] Taking the mean value of the number of elements in all subsequences within the resource usage sequence of each load parameter of each container with the same priority as the relative characteristic coefficient of each load parameter of each container.
[0021] Calculating the difference value between the relative characteristic coefficients of each load parameter of each container and the rest of the load parameters with the same priority, and taking the calculation result of the exponential function with the natural constant as the base and the difference value as the exponent as the second relative difference between each load parameter of each container and the rest of the load parameters with the same priority.
[0022] Preferably, determining the relative dynamic difference of each load parameter of each container with the same priority includes:
[0023] Calculating the ratio of the first relative difference to the second relative difference;
[0024] Taking the mean value of the ratio between each load parameter of each container and all the other load parameters with the same priority as the relative dynamic difference of each load parameter of each container with the same priority.
[0025] Preferably, determining the resource adjustment coefficient of each container with the same priority includes:
[0026] Calculating the similarity degree of the relative dynamic differences of all types of load parameters between each container and the rest of the containers with the same priority;
[0027] Taking the mean value of the similarity degree between each container and all the other containers with the same priority as the resource adjustment coefficient of each container with the same priority.
[0028] Preferably, performing resource configuration adjustment on containers with the same priority includes:
[0029] When a conflict occurs in the resource configuration with the same priority, sorting the resource adjustment coefficients of all containers with the same priority in descending order, and performing resource configuration adjustment on the containers with the same priority in the order of the sorting result.
[0030] In a second aspect, an embodiment of the present application further provides a policy orchestration response system based on containers, the system includes a memory, a processor, and a computer program stored in the memory and running on the processor, and when the processor executes the computer program, the steps of the above-mentioned policy orchestration response method based on containers are implemented.
[0031] In a third aspect, an embodiment of the present application further provides a computer storage medium storing a computer program, which when executed by a processor implements the method for container-based policy orchestration response described in any one of the above.
[0032] The present application has at least the following beneficial effects:
[0033] The present application divides the resource usage sequence into multiple subsequences; analyzes the central tendency of the element changes within each subsequence in the resource usage sequence and the fluctuation of the elements within the subsequence to obtain the local feature vectors of each subsequence; determines the dynamic eigenvalue of each subsequence in the resource usage sequence of each load parameter of each container under the same priority according to the similarity of the changes of the local feature vectors between different subsequences in the resource usage sequence. The beneficial effect is that it considers the local change trend and local fluctuation of each load parameter of containers with the same priority, and analyzes the similarity of the fluctuations in different local times to reflect the stability of the container load of the same priority in the local time, and further reflects the normal fluctuation degree of the container load in the corresponding local time; according to the distance relationship of all the dynamic eigenvalues between different load parameters of each container and the difference in the number of elements in all the subsequences, respectively determines the first relative difference and the second relative difference between each load parameter of each container and the remaining load parameters under the same priority; based on the first relative difference and the second relative difference, determines the relative dynamic difference of each load parameter of each container under the same priority. The beneficial effect is that it considers the dynamic difference of the fluctuations between different load parameters to reflect the significant influence of the dynamic changes of the load parameters on the resource configuration of different containers with the same priority; determines the resource adjustment coefficient of each container under the same priority according to the similarity of all the relative dynamic differences between each container and the remaining containers under the same priority; based on the resource adjustment coefficient, adjusts the resource configuration of the containers with the same priority; based on the container image and the resource allocation strategy of the resource configuration adjustment, deploys and monitors the containers through a container orchestration tool. The beneficial effect is that it considers the degree of dynamic change of different containers with the same priority to the load parameters, to reflect the influence of the dynamic changes of time on the container resource configuration, and the stability of the change characteristics of the load parameters in a relatively long time range. Furthermore, when there are conflicts in the resource configuration of the same priority, the resource configuration is dynamically adjusted to ensure that the application program can run consistently in any environment, improving the response speed, accuracy, and efficiency of network security events. Description of the Drawings
[0034] The following further elaborates on the method for container-based policy orchestration response of the present application with reference to the drawings.
[0035] Figure 1The flowchart of the steps of the container-based policy orchestration response method provided by the embodiments of the present application;
[0036] Figure 2 The flowchart of the steps of the method for obtaining the dynamic characteristic values of each subsequence in the resource usage sequence of each load parameter of each container under the same priority provided by the embodiments of the present application;
[0037] Figure 3 The flowchart of the steps of the method for obtaining the relative dynamic differences of each load parameter of each container under the same priority provided by the embodiments of the present application. Detailed implementation manners
[0038] In order to make the objectives, technical solutions and advantages of the present application clearer, the container-based policy orchestration response method, system and computer storage medium proposed by the present application will be further described in detail below with reference to the accompanying drawings and implementation examples. It should be understood that the specific implementation examples described herein are only used to explain the present application and are not used to limit the present application.
[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs.
[0040] Please refer to Figure 1 , which shows the flowchart of the steps of the container-based policy orchestration response method provided by an embodiment of the present application. The method includes the following steps:
[0041] Step 1, build a container image through a container engine; obtain the resource usage data of each load parameter of each container with the same priority on the nodes in the cluster, and form a resource usage sequence for each load parameter. The load parameters include: CPU usage rate, memory usage rate, and network bandwidth usage.
[0042] In the current container technology, Docker container runtime is the most widely used. A container is an independent and lightweight runtime environment that includes application code, runtime libraries, system tools, and system libraries. Containers are isolated, each with its own file system and process space, isolated from the host system and other containers. This isolation prevents containers from interfering with each other, even if they are running on the same physical host. These basic concepts of container technology make it an ideal choice for modern application development and deployment, providing high flexibility, maintainability, and resource isolation, while reducing the complexity of deployment and management.
[0043] Containerization technology is a virtualization technology that allows developers to encapsulate an application and all its dependencies in an independent container. The container uses a container engine, such as Docker, to create, manage, and run.
[0044] First, install the Docker engine running environment in the application system. According to the requirements of application components, create a Dockerfile. The Dockerfile is a text file used to define how to build a Docker container. The Dockerfile includes steps such as the base image, working directory, installation of dependencies, and copying of application code. Use the container building tool Docker technology to build a container image according to the Dockerfile.
[0045] It should be noted that the method of creating a Docker container image using Docker technology is a well-known technology and will not be elaborated here.
[0046] Furthermore, use a container orchestration tool to deploy and manage the built container images. Container orchestration is a key automation tool and method for effectively managing and coordinating the deployment and operation of containerized applications. The main goal is to simplify the management of container clusters and provide high availability, scalability, and automated container management. The container orchestration tool is responsible for allocating containers to available computing resources and automatically handling communication and load balancing between containers to ensure the availability of applications. Container orchestration tools, such as Kubernetes, improve the management efficiency of containerized applications, enabling automatic scaling, automatic repair, and load balancing, thus ensuring high availability.
[0047] When using the Kubernetes orchestration tool to allocate resources, it is a single-threshold resource configuration. Resources are mainly allocated and adjusted by defining resource requests and resource limits for containers in Kubernetes. For example, according to the resource requests and resource limits defined for each container, the resource quotas allocated after partitioning by application components, and the defined priorities, resources are configured. However, this resource configuration method does not consider the dynamic changes in the resource requirements of containers. When resource conflicts occur, low-priority container sets (pods) will be evicted to ensure the normal supply of resources for high-priority pods, but it cannot avoid resource conflict problems among pods with the same priority. Therefore, by analyzing the dynamic changes in the resource requirements of pods with the same priority, optimize and adjust the resource allocation to improve resource utilization.
[0048] A Kubernetes cluster consists of multiple nodes. A node is a machine that performs specific tasks. It can be a virtual machine or a physical machine. Pods are distributed on nodes according to the scheduling configuration. Each node can have multiple Pods, and each pod can contain one or more containers. By collecting the container resource usage of all containers in all pods on the node, the priorities of all containers in pods with the same priority are also the same.
[0049] Therefore, before deploying the container image, it is necessary to define a resource allocation strategy to guide the system operation when resource configuration conflicts occur.
[0050] The Agent on the node regularly samples the container resource usage under the same priority through Docker-Daemon, obtains the usage data of each type of load in the container, samples the container N times, forms a sequence according to the collection order, and obtains the resource usage sequence of each type of load parameter of each container under the same priority. Each type of load parameter includes: CPU usage rate, memory usage rate, and network bandwidth usage.
[0051] Preferably, in this embodiment, the container is sampled 500 times. As other implementation manners, the implementer can set it according to the actual situation.
[0052] So far, the resource usage sequence of each type of load parameter of each container under the same priority is obtained.
[0053] Step 2: Divide the resource usage sequence into multiple subsequences; analyze the central tendency of the element changes within each subsequence of the resource usage sequence, as well as the fluctuation of the elements within the subsequence, to obtain the local feature vectors of each subsequence; determine the dynamic characteristic values of each subsequence within the resource usage sequence of each type of load parameter of each container under the same priority according to the similarity of the changes of the local feature vectors between different subsequences within the resource usage sequence.
[0054] To clarify the dynamic change characteristics of the load of each container under the same priority over time, by analyzing the local change trend and local fluctuation degree of each type of load parameter, the dynamic characteristic value is determined to reflect the dynamic difference situation of the container resources over time. Specifically:
[0055] Divide the resource usage sequence of each type of load parameter of each container under the same priority into multiple subsequences;
[0056] Preferably, in this embodiment, the Bernaola Galvan segmentation algorithm is used to divide the resource usage sequence into multiple subsequences. Among them, the Bernaola Galvan segmentation algorithm is a well-known technology and will not be elaborated here.
[0057] Calculate the trend statistic and coefficient of variation of each subsequence within the resource usage sequence;
[0058] Preferably, in this embodiment, the Mann-Kendall trend test algorithm is used to obtain the trend statistic of each subsequence. Among them, the calculation of the Mann-Kendall trend test algorithm and the coefficient of variation are both well-known technologies and will not be elaborated here.
[0059] Combine the trend statistic and the coefficient of variation to form the local feature vector of each subsequence;
[0060] It should be noted that the trend statistic reflects the central tendency of the subsequence, and the coefficient of variation reflects the degree of fluctuation of the elements within the subsequence.
[0061] Calculate the mean of the point sets of the local feature vectors of each subsequence in the resource usage sequence with all other subsequences as the dynamic eigenvalue of each subsequence in the resource usage sequence of each load parameter of each container under the same priority;
[0062] Preferably, in this embodiment, the calculation formula for the dynamic eigenvalue of each subsequence in the resource usage sequence of each load parameter of each container under the same priority is: Where, is the dynamic eigenvalue of the k-th subsequence in the resource usage sequence of the r-th load parameter of the m-th container under the same priority, is the local feature vector of the k-th subsequence in the resource usage sequence of the r-th load parameter of the m-th container under the same priority, is the local feature vector of the g-th subsequence in the resource usage sequence of the r-th load parameter of the m-th container under the same priority, dpr() is to calculate the dot product of vectors, G m,r is the number of all subsequences in the resource usage sequence of the r-th load parameter of the m-th container under the same priority.
[0063] It should be noted that the larger the dynamic eigenvalue, the smaller the difference in the fluctuation changes of the container's usage of the load parameter in the local time period, that is, the local dynamic change is more stable in a longer time. Among them, the dot product reflects the similarity of vectors in the multi-dimensional space. If the dynamic eigenvalue is larger, it indicates that the resource usage situation of the corresponding subsequence is similar to that of other subsequences, indicating that it may be a normal load change.
[0064] Furthermore, the step flow chart of the method for obtaining the dynamic eigenvalue of each subsequence in the resource usage sequence of each load parameter of each container under the same priority provided by the embodiment of the present application is as Figure 2 shown.
[0065] So far, the dynamic eigenvalue of each subsequence in the resource usage sequence of each load parameter of each container under the same priority is obtained.
[0066] Step 3: According to the distance relationships among all the dynamic eigenvalue between different load parameters of each container, and the differences in the number of elements within all the subsequences, respectively determine the first relative difference and the second relative difference between each load parameter of each container and the remaining load parameters under the same priority; Based on the first relative difference and the second relative difference, determine the relative dynamic difference of each load parameter of each container under the same priority.
[0067] Further, analyze the difference in the duration range of the resource usage of each load parameter of each container over time under the same priority, and the dynamic difference in the resource allocation process of different load parameters over time, and determine the relative dynamic difference, specifically:
[0068] Take the mean value of the number of elements within all the subsequences in the resource usage sequence of each load parameter of each container under the same priority as the relative characteristic coefficient of each load parameter of each container;
[0069] Form the dynamic eigenvalue within all the subsequences in the resource usage sequence of each load parameter of each container under the same priority into a dynamic eigenvalue sequence;
[0070] Denote the distance between the dynamic eigenvalue sequence of each load parameter of each container and the remaining load parameters under the same priority as the first relative difference;
[0071] Preferably, in this embodiment, denote the DTW distance between the dynamic eigenvalue sequence of each load parameter of each container and the remaining load parameters under the same priority as the first relative difference, where the calculation of the DTW distance is a well-known technology and will not be elaborated here.
[0072] Calculate the difference value between the relative characteristic coefficients of each load parameter of each container and the remaining load parameters under the same priority, and denote the calculation result of the exponential function with the natural constant as the base and the difference value as the exponent as the second relative difference;
[0073] Preferably, in this embodiment, calculate the absolute value of the difference between the relative characteristic coefficients of each load parameter of each container and the remaining load parameters under the same priority, and denote the calculation result of the exponential function with the natural constant as the base and the absolute value as the exponent as the second relative difference.
[0074] Calculate the ratio of the first relative difference and the second relative difference between each load parameter of each container and the remaining load parameters under the same priority;
[0075] Take the mean value of the ratio between each load parameter of each container and all the remaining load parameters under the same priority as the relative dynamic difference of each load parameter of each container;
[0076] Preferably, in this embodiment, the calculation formula for the relative dynamic difference of each load parameter of each container under the same priority is as follows: where C m,r is the relative dynamic difference of the r-th load parameter of the m-th container under the same priority, w m,r is the dynamic feature sequence of the r-th load parameter of the m-th container under the same priority, w m,x is the dynamic feature sequence of the x-th load parameter of the m-th container under the same priority, a m,r is the relative feature coefficient of the r-th load parameter of the m-th container under the same priority, a m,x is the relative feature coefficient of the x-th load parameter of the m-th container under the same priority, dtw() represents calculating the DTW distance, exp() is the exponential function with the natural constant as the base, and R m is the number of all load parameters of the m-th container under the same priority.
[0077] It should be noted that the greater the first relative difference, the greater the difference in resource usage between different load parameters; the greater the second relative difference, the smaller the difference in the usage duration of resource usage for different load parameters; the greater the obtained relative dynamic difference, the more significant the impact of the dynamic change of load parameters on the container resource configuration.
[0078] Furthermore, the step flow chart of the method for obtaining the relative dynamic difference of each load parameter of each container under the same priority provided by the embodiment of the present application is as Figure 3 shown.
[0079] Thus, the relative dynamic difference of each load parameter of each container under the same priority is obtained.
[0080] Step 4, determine the resource adjustment coefficient of each container under the same priority according to the similarity of all the relative dynamic differences between each container and the remaining containers under the same priority; based on the resource adjustment coefficient, adjust the resource configuration of the containers under the same priority; based on the container image and the resource allocation strategy of the resource configuration adjustment, deploy and monitor the containers through the container orchestration tool.
[0081] Furthermore, based on the relative dynamic difference, analyze the dynamic change situation of load parameters between different containers under the same priority, determine the resource adjustment coefficient to reflect the stability of resource usage for the containers to withstand the load, so as to prioritize resource configuration for them. Specifically:
[0082] Calculate the similarity degree of the relative dynamic differences of all types of load parameters between each container and the remaining containers at the same priority level; use the average value of the similarity degrees of each container and all the remaining containers at the same priority level as the resource adjustment coefficient of each container at the same priority level.
[0083] Preferably, in this embodiment, calculate the cosine similarity of the relative dynamic differences of all types of load parameters between each container and the remaining containers at the same priority level. The calculation of the cosine similarity is a well-known technology and will not be elaborated here.
[0084] It should be noted that the larger the resource adjustment coefficient, the more consistent the dynamic change characteristics of the resources of different containers based on the same priority level over time, indicating that the current container resource configuration is less affected by dynamic changes over time, that is, the change characteristics of the load parameters are more stable within a relatively long time range. Therefore, the resource configuration of the container can be prioritized.
[0085] When there are conflicts in the resource configuration at the same priority level, sort the resource adjustment coefficients of all containers at the same priority level in descending order, and adjust the resource configuration of the containers at the same priority level in the order of the sorting results.
[0086] Based on the constructed container images and the formulated resource allocation strategy, use the Kubernetes orchestration tool for deployment and monitoring, specifically including:
[0087] According to the defined container images and resource allocation strategy, create corresponding resource objects in Kubernetes. Configure the network connection of the container. Kubernetes uses network plugins to implement communication between containers and between containers and the external network. Expose the service ports inside the container to the inside or outside of the cluster by setting the Service resource so that other components or users can access. For application components that need to persistently store data, configure the storage volume and use cloud storage as the backend of the storage volume. Ensure that the container can access and use the persistently stored data by specifying the storage volume mount point in the definition of the Pod. Use the command-line tool of Kubernetes to apply the created resource objects to the Kubernetes cluster. Kubernetes automatically pulls the container image, starts the container, and configures it according to the strategy.
[0088] Provide built-in monitoring metrics through Kubernetes itself to monitor the running status of containers and clusters in real time, such as CPU usage, memory usage, network bandwidth, etc. And make dynamic adjustments according to the monitored container resource usage. For example, if the CPU usage of a certain container continuously exceeds the set threshold, Kubernetes can automatically trigger the horizontal scaling mechanism. Through the Horizontal Pod Autoscaler (HPA), automatically adjust the number of container instances according to the CPU usage to share the load and reduce the CPU usage of a single container.
[0089] Listen for container-related events, including container startup, stop, and failure events. When an event occurs, Kubernetes can make dynamic adjustments according to predefined policies. For example, when a container fails, according to the recovery policy, Kubernetes can automatically restart the container or switch to a standby container.
[0090] It should be noted that the process of deploying containers through container orchestration is a well-known technology and will not be elaborated here.
[0091] The embodiment of the present application also provides a container-based policy orchestration response system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the container-based policy orchestration response method described in any one of the above.
[0092] Based on the same inventive concept as the above method, the embodiment of the present application also provides a computer storage medium. The computer storage medium stores a computer program, and when the program is executed by a processor, it implements the container-based policy orchestration response method described in any one of the above.
[0093] It should be understood that although Figure 1 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figure 1 at least a part of the steps in
[0094] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0095] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but should not be construed as a limitation to the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made. Therefore, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present application without departing from the content of the technical solution of the present application all fall within the protection scope of the technical solution of the present application.
Claims
1. A container-based policy orchestration response method, characterized in that: The method comprises the following steps: Build a container image through the container engine; obtain resource usage data of each load parameter of each container at the same priority on the nodes in the cluster, and form a resource usage sequence for each load parameter, wherein the load parameters include: CPU usage, memory usage, and network bandwidth usage; The resource usage sequence is divided into a plurality of subsequences; a central trend of element changes in each subsequence of the resource usage sequence and fluctuations of elements in the subsequence are analyzed to obtain a local feature vector of each subsequence; and a dynamic feature value of each subsequence in the resource usage sequence for each load parameter of each container at the same priority is determined according to similarities in changes of the local feature vectors between different subsequences in the resource usage sequence; The dynamic feature values of all subsequences in the resource usage sequence are combined into a dynamic feature sequence; Taking the distance of the dynamic feature sequence between each load parameter of each container and the remaining load parameters under the same priority as the first relative difference between each load parameter of each container and the remaining load parameters under the same priority; The average of the number of elements in all subsequences in the resource usage sequence of each load parameter of each container at the same priority level is used as the relative characteristic coefficient of each load parameter of each container; Calculate the absolute value of the difference between the relative characteristic coefficients of each load parameter of each container at the same priority and the remaining load parameters, and use the calculation result of an exponential function with a natural constant as the base and the absolute value of the difference as the exponent as the second relative difference between each load parameter of each container at the same priority and the remaining load parameters; determine the relative dynamic difference of each load parameter of each container at the same priority based on the first relative difference and the second relative difference; Determine a resource adjustment coefficient for each container at the same priority level according to similarities of all the relative dynamic differences between each container at the same priority level and the other containers; and adjust resource configuration for the containers at the same priority level based on the resource adjustment coefficient; Based on the container image and the resource allocation strategy adjusted by the resource configuration, the container is deployed and monitored through the container orchestration tool.
2. The container-based policy orchestration response method according to claim 1, characterized in that: The obtaining of the local feature vector of each subsequence includes: Calculating trend statistics and coefficient of variation for each subsequence within the resource usage sequence; The trend statistic and the coefficient of variation are combined to form a local feature vector of each subsequence.
3. The container-based policy orchestration response method according to claim 1, characterized in that: The dynamic feature value of each subsequence in the resource usage sequence of each load parameter of each container at the same priority is the average of the dot products of the local feature vectors of each subsequence in the resource usage sequence and all other subsequences.
4. The container-based policy orchestration response method according to claim 1, characterized in that: The determining of the relative dynamic difference of each load parameter of each container at the same priority level includes: calculating a ratio of the first relative difference to the second relative difference; The average of the ratios between each load parameter of each container at the same priority and all other load parameters is taken as the relative dynamic difference of each load parameter of each container at the same priority.
5. The container-based policy orchestration response method according to claim 1, characterized in that: The determining of the resource adjustment coefficient of each container at the same priority level includes: Calculating the similarity of the relative dynamic differences of all kinds of load parameters between each container and other containers at the same priority level; The average of the similarities between each container and all other containers at the same priority level is used as the resource adjustment coefficient of each container at the same priority level.
6. The container-based policy orchestration response method according to claim 1, characterized in that: The adjusting resource configuration for containers of the same priority level includes: When conflicts occur in resource configurations of the same priority, the resource adjustment coefficients of all containers of the same priority are sorted in descending order, and resource configurations of the containers of the same priority are adjusted in sequence according to the sorting results.
7. A container-based policy orchestration response system, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the container-based policy orchestration response method as described in any one of claims 1 to 6 when executing the computer program.
8. A computer storage medium storing a computer program, characterized in that: When the program is executed by a processor, the container-based policy orchestration response method as described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Distributed storage container scheduling method and device, electronic equipment and readable medium
CN116737310A
Container cloud resource intelligent scheduling system based on delay perception and working method
CN118331738A