Multi-tenant-oriented deployment method and device, equipment, medium and program product

By receiving deployment requests, matching resources, distributing file packages and executing templates in a multi-tenant environment, the problem of achieving rapid and automated deployment when the existing resource environment is small is solved, and deployment efficiency and resource utilization are improved.

CN119960766APending Publication Date: 2025-05-09CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411797880.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In a multi-tenant environment, how to quickly and automatically deploy applications and improve resource utilization while transforming the existing resource environment is very small.

Method used

By receiving deployment requests from the target application, matching deployment resources, determining the target deployment node, and distributing deployment program file packages. Determine the target template from the preconfigured multi-function template, execute the target template according to the deployment program file package, and deploy the target application to the target deployment node.

Benefits of technology

It significantly improves deployment efficiency and accuracy, ensures the security of the deployment process, and improves resource utilization and application performance through dynamic resource allocation algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119960766A_ABST
    Figure CN119960766A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software development, and discloses a multi-tenant-oriented deployment method and device, equipment, a medium and a program product, and the method comprises the steps: receiving a deployment request of a target application; in response to the deployment request, performing deployment resource matching, and determining a target deployment node; distributing the deployment program file package of the target application to the target deployment node; a target template corresponding to the target application is determined from a plurality of pre-configured multifunctional templates, the target template is a pre-configured atomic template segment or the target template comprises a plurality of pre-configured atomic template segments, and the atomic template segments are used for representing function definition of the application program; according to the deployment program file package, executing the target template, and deploying the target application to the target deployment node; and receiving a deployment result of the target application. According to the embodiment of the invention, the target application is deployed at the target deployment node by matching the deployment resources, determining the target deployment node and deploying the target application at the target deployment node through the pre-configured multifunctional template, so that the deployment efficiency and accuracy are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software development, and in particular to a multi-tenant-oriented deployment method, device, equipment, medium and program product. Background Art

[0002] Multi-tenant architecture is a software architecture and deployment method that allows a single application or system to serve multiple different customers at the same time. In this case, the application is designed to run for multiple independent customers or tenants in the same environment, and each tenant remains isolated from each other. Usually, each tenant has its own data, settings, user management, security policies, etc. This is because each customer needs to ensure that their data is secure and not interfered with by other customers. The two common types of multi-tenant architecture are software as a service (SaaS) and platform as a service (PaaS). Among them, SaaS is a cloud computing-based delivery model in which vendors provide software application services to users over the Internet. Each customer can subscribe and use their own independent instance without purchasing and maintaining hardware and software infrastructure. PaaS provides a platform for developing and deploying applications, allowing developers to quickly create and expand applications. In a multi-tenant PaaS environment, each tenant can use an independent instance or container to deploy and run their own application without affecting other tenants.

[0003] In a multi-tenant scenario, how to quickly and automatically deploy applications has always been a direction that everyone is actively exploring, especially how to reuse old resources, how to improve resource utilization, and how to activate resources, which is the focus of everyone's research. In related technologies, there is a way to build a multi-tenant CICD process based on the field of K8s intelligent scheduling technology. However, this method requires a lot of changes to the existing resource environment and has low resource utilization. Therefore, how to implement application deployment in a multi-tenant environment with little change to the existing resource environment is still a technical problem that needs to be solved in this field. Summary of the invention

[0004] In view of this, the present invention provides a multi-tenant-oriented deployment method, apparatus, device, medium and program product to solve the problem of how to implement application deployment in a multi-tenant environment with minimal modification to the existing resource environment.

[0005] In a first aspect, the present invention provides a multi-tenant deployment method, the method comprising:

[0006] Receive a deployment request from a target application;

[0007] In response to the deployment request, perform deployment resource matching and determine the target deployment node;

[0008] Distribute the deployment program file package of the target application to the target deployment node;

[0009] Determining a target template corresponding to a target application from a plurality of pre-configured multifunctional templates, wherein the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, and the atomic template fragment is used to characterize a function definition of the application program;

[0010] According to the deployment program file package, execute the target template and deploy the target application to the target deployment node;

[0011] Receive the deployment results of the target application.

[0012] The multi-tenant deployment method of the embodiment of the present invention receives a deployment request of a target application, performs deployment resource matching in response to the deployment request, and determines a target deployment node; distributes a deployment program file package of the target application to the target deployment node, determines a target template corresponding to the target application from a plurality of pre-configured multifunctional templates, the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, the atomic template fragments are used to characterize the functional definition of the application, executes the target template according to the deployment program file package, deploys the target application to the target deployment node, and receives the deployment result of the target application. In this way, the target deployment node is determined by deployment resource matching, and the target application is deployed at the target deployment node through the pre-configured multifunctional template, which significantly improves the deployment efficiency and accuracy.

[0013] In an optional implementation, before distributing the deployment program file package of the target application to the target deployment node, the method further includes:

[0014] Perform image resource security audit on deployment program files.

[0015] The multi-tenant deployment method of the embodiment of the present invention performs a mirror resource security audit on the deployment program file before distributing the deployment program file package of the target application to the target deployment node. The program file is tracked throughout the entire process to effectively ensure the security of the deployment process.

[0016] In an optional implementation, in response to a deployment request, performing deployment resource matching and determining a target deployment node includes:

[0017] Determine the amount of resources requested for the target application;

[0018] When the amount of resources applied for is not greater than the total amount of resources, the initial matching is determined to be successful;

[0019] Correct the resource application amount;

[0020] Polling is performed based on the revised applied resource amount and the resource margins of the multiple resource nodes, and a resource node whose resource margin is greater than the revised applied resource amount among the multiple resource nodes is determined as a target deployment node.

[0021] In an optional implementation, in response to the deployment request, performing deployment resource matching and determining the target deployment node further includes:

[0022] Dynamically adjust the optimization factor for correcting the resource application amount to dynamically correct the resource application amount.

[0023] The multi-tenant deployment method of the embodiment of the present invention determines the amount of resources applied for the target application, and when the amount of resources applied is not greater than the total amount of resources, determines that the initial matching is successful, and corrects the amount of resources applied, and polls based on the corrected amount of resources applied and the resource margin of multiple resource nodes, and determines that the resource node whose resource margin is greater than the corrected amount of resources applied is the target deployment node. Further, the optimization factor for correcting the amount of resources applied is dynamically adjusted to dynamically correct the amount of resources applied. Thus, by using a dynamic resource allocation algorithm, resource allocation can be dynamically adjusted according to the real-time needs and resource usage of the application program to improve resource utilization and the performance of the application program. The dynamic resource allocation algorithm can also add a resource preemption strategy to more flexibly adjust resource allocation to meet the real-time needs of the application program. And based on the cyclic feedback of the optimization factor, the optimization factor is adjusted dynamically and resource allocation is optimized to improve the overall performance and efficiency of the multi-tenant deployment method.

[0024] In an optional implementation, the method is applied to a deployment management unit; before receiving a deployment request of a target application, the method further includes:

[0025] Install agent units on multiple resource nodes. The agent units have the address of the deployment management unit built in.

[0026] Receiving the physical machine host information of the multiple resource nodes obtained by the agent unit to the deployment management unit;

[0027] Based on the physical host information of multiple resource nodes, create management records for multiple resource nodes.

[0028] The multi-tenant deployment method of the embodiment of the present invention dynamically manages resource nodes through an agent unit, thereby effectively improving the resource management efficiency and accuracy of resource nodes capable of deploying application programs.

[0029] In an optional implementation, before receiving the deployment request of the target application, the method further includes:

[0030] Configure multiple atom template fragments;

[0031] According to the functional requirements of the application, the atomic template fragments are combined to obtain multiple multifunctional templates;

[0032] Create template libraries for managing atomic template fragments and multi-purpose templates.

[0033] The multi-tenant deployment method of the embodiment of the present invention realizes flexible and maintainable deployment templates by defining atomic template fragments, establishing a template library, etc. Therefore, a multifunctional template that adapts to different needs can be quickly constructed by adjusting template parameters and combining different template fragments, thereby improving deployment efficiency and accuracy.

[0034] In a second aspect, the present invention provides a multi-tenant deployment device, the device comprising:

[0035] A receiving module, used for receiving a deployment request of a target application;

[0036] A node determination module is used to respond to a deployment request, match deployment resources, and determine a target deployment node;

[0037] A distribution module, used to distribute the deployment program file package of the target application to the target deployment node;

[0038] a target determination module, used to determine a target template corresponding to a target application from a plurality of pre-configured multifunctional templates, wherein the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, and the atomic template fragment is used to characterize a function definition of the application program;

[0039] A deployment module is used to execute the target template according to the deployment program file package and deploy the target application to the target deployment node;

[0040] The result acquisition module is used to receive the deployment result of the target application.

[0041] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the multi-tenant deployment method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0042] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the multi-tenant deployment method of the first aspect or any corresponding embodiment thereof.

[0043] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the multi-tenant deployment method of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0045] Figure 1 is a schematic diagram of a specific application scenario of a multi-tenant deployment method according to an embodiment of the present invention;

[0046] Figure 2 is a flowchart of a multi-tenant deployment method according to an embodiment of the present invention;

[0047] Figure 3 is a flow chart of recording deployment results in a multi-tenant-oriented deployment method according to an embodiment of the present invention;

[0048] Figure 4 is a flow chart of another multi-tenant-oriented deployment method according to an embodiment of the present invention;

[0049] Figure 5 is a structural block diagram of a multi-tenant deployment device according to an embodiment of the present invention;

[0050] Figure 6 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0051] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0052] In order to better illustrate the specific solutions of the embodiments of the present invention, the application scenarios of the embodiments of the present invention are first exemplarily described here. Figure 1 Schematic diagram of a specific application scenario of a multi-tenant deployment method according to an embodiment of the present invention. Figure 1As shown, in the multi-tenant deployment method of the embodiment of the present invention, a deployment management unit can be pre-configured to manage multiple servers. Figure 1 As a multi-tenant deployment system, the system mainly consists of three parts: a deployment management unit 101, multiple agent units (agents) and multiple resource nodes. Figure 1 In the figure, multiple agent units are represented by agent unit 121, agent unit 122, agent unit 123 and agent unit 123, and multiple resource nodes are represented by resource node 131, resource node 132, resource node 133 and resource node 133. In actual applications, the number of agent units and resource nodes can be configured and set according to actual needs, and the present invention does not make specific limitations on this. The deployment management unit can manage all resource nodes and manage automatic deployment tasks through agent units. The agent unit is used to automatically report physical machine information, receive and execute deployment tasks, etc. Resource nodes are used to carry and run deployed applications.

[0053] According to an embodiment of the present invention, a multi-tenant deployment method embodiment is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0054] In this embodiment, a multi-tenant deployment method is provided, which can be used for servers, etc. Figure 2 is a flowchart of a multi-tenant deployment method according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0055] Step S201: receiving a deployment request of a target application.

[0056] In some optional implementations, when an application needs to be deployed, it can be done by being able to communicate with Figure 1 The deployment management unit communicates with the HTTP page of the client, etc., and sends the deployment request of the target application to the deployment management unit. The deployment management unit can be configured on a server.

[0057] Step S202: In response to the deployment request, deployment resource matching is performed to determine a target deployment node.

[0058] In some optional implementations, a two-layer matching strategy for deployment resource matching may be pre-configured, wherein the first layer of initial matching uses preset rules or manual configuration to allocate initial resources, and the second layer of matching strategy uses dynamic matching to perform dynamic resource checks.

[0059] Specifically, the remaining resources of multiple resource nodes can be obtained and dynamically updated. Furthermore, for a target application that needs to be deployed, the resource requirement for deploying the target application can be carried in the target request. When at least one resource node among the multiple resource nodes can meet the resource requirement of the target application, it is determined to deploy the target application on the resource node.

[0060] In some optional implementations, the ansible tool may be used to perform the automated application deployment operations of step S202 to step S206. Ansible is a simple and easy-to-use automation tool that can automate various tasks, such as configuration management, application deployment, script execution, etc. It uses a template-based architecture, can be integrated with other tools, and does not require the installation of client software on the remote host.

[0061] Here, the deployment management unit can remotely access the target node through SSH (Secure Shell, a network protocol), and the target node can be the above Figure 1 One of the resource nodes 131 to 134 in the deployment. SSH can be used to encrypt remote login sessions and other network services. The SSH protocol can effectively prevent information from being leaked and tampered with during transmission. Use the Ansible tool to connect to the target node to be deployed through the SSH protocol. This step ensures that the target node can be remotely controlled and operated.

[0062] Furthermore, you can also perform application updates for deployed applications. Here, you can first back up the deployed applications. The backup content includes application system program files, configuration files, startup scripts, etc. The backup results need to be marked with tags, which contain version information and the date of the backup. In this way, you can effectively avoid deployment failures due to unexpected situations during the deployment process, and at the same time, you can also retain the original version of the application file package.

[0063] Step S203: distribute the deployment program file package of the target application to the target deployment node.

[0064] Specifically, here you can use the ansible tool to distribute the deployment program file package of the target application to the target deployment node by copying without secrets. The image used for deployment needs to be pulled to the target deployment node to be deployed first. This step ensures that the program file package of the application can be correctly transferred to the target deployment node.

[0065] Step S204, determining a target template corresponding to the target application from a plurality of pre-configured multifunctional templates, where the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, and the atomic template fragment is used to represent the function definition of the application program.

[0066] In some optional embodiments of the present invention, a template library may be predefined, and the template library may include preconfigured atomic template fragments and multifunctional templates composed of multiple atomic template fragments.

[0067] Taking a web application as an example, the following atomic template fragments can be defined:

[0068] 1) Docker image template fragment: responsible for pulling and preparing the required application Docker image from Docker Hub or elsewhere.

[0069] 2) Environment variable template fragment: can be used to define the environment variables required for the application to run.

[0070] 3) Port mapping template fragment: used to map the port inside the container to the public port on the host.

[0071] 4) Health check template snippet: Perform periodic or conditionally triggered health checks to ensure that the application is running properly.

[0072] Furthermore, these basic atomic template fragments can be combined to form a multi-functional template fragment, such as "Start Web Application". Then, create a template library for managing atomic template fragments and multi-functional templates. When you need to deploy a new Web application, you can directly use this multi-functional template of "Start Web Application". You only need to fill in the necessary parameters, such as Docker (container) image name, environment variable value, port, etc., to quickly complete the entire deployment process.

[0073] Better yet, use a version control system to track version changes of multiple multi-functional templates in the template library, so as to update and roll back the versions of the multi-functional templates, and provide an easy-to-use dashboard to assist users in using templates.

[0074] Step S205: execute the target template according to the deployment program file package, and deploy the target application to the target deployment node.

[0075] In some optional implementations, the target application can be quickly deployed to the target deployment node by executing the target template based on the ansible tool according to the deployment program file package.

[0076] Specifically, the target application can be automatically deployed by executing the target template through Ansible. All the configuration information required for the application can be pre-defined in the target template, thereby ensuring that the application of the target application is deployed according to the preset configuration and automatically handling some complex configuration issues.

[0077] Step S206, receiving the deployment result of the target application.

[0078] In some optional implementations, after the automated deployment task of the target application is completed, such as Figure 1 The agent unit shown can monitor deployment tasks, initiate health checks, check deployment results and report to the dpserver (deployment management unit). The dpserver selects an appropriate notification method based on the notification person information, and sends the deployment results of the target application to the user end that issued the deployment request.

[0079] The dpserver mentioned here and elsewhere in this article can be Figure 1 The deployment management unit 101 is shown.

[0080] Figure 3 FIG. 2 shows a flow chart of recording deployment results according to an embodiment of the present invention. Figure 3 As shown in the figure, after the automated deployment task is completed, the agent unit listens to the deployment task and initiates a health check, which specifically includes the following process:

[0081] Step S301: The automated deployment task completes application deployment.

[0082] The agent unit deploys the application through the Ansible automated script execution deployment template, and the script execution results are synchronously recorded in the Agent log.

[0083] Step S302: The agent monitors the deployment task and completes it. The agent monitors the deployment task and enters S3 after the application is deployed.

[0084] In step S303, the agent unit may initiate a health check according to a preset health check rule.

[0085] For interface-based dialing, directly dial the application / health interface, and the http request status code 200 can determine that the application deployment and startup are successful. For non-interface-based dialing, use process monitoring and other methods to perform dialing. If the process exists, the deployment is successful, and then go to step S305. If the check fails, go to step S304.

[0086] Step S304, determining whether the health check is initiated successfully, and determining the number of retries.

[0087] If the health check is not initiated successfully, step S303 is executed again.

[0088] If the health check is successfully initiated, step S305 is executed.

[0089] If the health check is not initiated successfully and the retry number reaches the maximum number N, the retry is successful, and step S305 is executed. If the retry number reaches the maximum number N and the retry still fails, the retry is terminated and step S306 is executed to record the detection failure.

[0090] Step S305: the proxy unit initiates a request to report a successful deployment result.

[0091] Step S306: The proxy unit initiates a deployment failure result reporting request.

[0092] Step S307: the proxy unit establishes a connection with the dpserver.

[0093] Here, the connection with the dpserver can be established through the dpserver address and key built into the proxy unit. Here, multiple attempts to connect can also be made. If the connection fails, retries are performed until the maximum number of retries M is reached, and then step S309 is entered. If the connection is established successfully or the retry is successful, step S308 is entered.

[0094] Step S307: the proxy unit initiates a deployment failure result reporting request.

[0095] The agent fails to establish a connection, and the agent unit records the failure log.

[0096] Step S308: dpserver receives the deployment task completion information. dpserver first verifies the signature to ensure that the request has not been tampered with. After completing the signature verification, it performs information parsing and structural processing. After the processing is completed, it executes step S309.

[0097] Step S309: dpserver updates the deployment task completion information. The structured data formed in step S308 is stored in the db of dpserver, completing the update of the status information of the deployment task.

[0098] Step S310: notify the agent of the completion of the update through the callback mechanism. The interface will contain callback address callbackurl information, and the dbserver notifies the agent of the completion of the update through callbackurl.

[0099] Step S312, dpserver queries the information of the notifier. dpserver obtains the configured notifier information through db query, assembles the data, and prepares the notification data.

[0100] Step S313, dpserver queries the notification method. dpserver queries the configured notification method through the database, supporting multiple methods such as SMS, enterprise WeChat, and email.

[0101] Step S314, dpserver sends a notification of the deployment result.

[0102] The dpserver sends the deployment result to the client that issued the deployment request through the notification channel of S313. The user at the client receives the notification and can learn the result of the deployment task execution in a timely manner.

[0103] It should be noted that the proxy unit in steps S301 to S314 may be a proxy unit corresponding to the target node. Figure 1 , the target node is the resource node 1031, then the proxy unit may be the proxy unit 1021.

[0104] In this embodiment, a multi-tenant deployment method is provided, which can be used for servers, etc. Figure 4 is a flowchart of another multi-tenant deployment method according to an embodiment of the present invention. Figure 4 As shown, the process includes the following steps:

[0105] Step S401: manage multiple resource nodes.

[0106] Specifically, step S401 may include:

[0107] Step S4011, installing agent units on multiple resource nodes, the agent units having built-in addresses of deployment management units.

[0108] The deployment management unit (dpserver for short) can be used to manage resource nodes and automatic deployment tasks. There are two management methods: manual management, in which physical machine information is manually entered through the Dashboard, including but not limited to: operating system, operating system version, CPU architecture, physical CPU, physical memory, physical storage and other information.

[0109] Step S4012, receiving the physical machine host information of the multiple resource nodes acquired by the agent unit to the deployment management unit.

[0110] Step S4013: Create management records for the multiple resource nodes based on the physical machine host information of the multiple resource nodes.

[0111] The automatic discovery strategy applied to the management process of the resource node in step S401 may include the following steps:

[0112] Step a1: Install the agent unit on the physical machine to be managed.

[0113] The agent unit has a built-in deployment management unit dpserver address. The agent can be installed with one click using the curl command. The following is a simple Linux one-click installation example:

[0114] curl-sL

[0115] 'http: / / IP:PORT / agent / download? k=xxx&group=x&protocol=x&runAccount=xx&certId=xx'|bash

[0116] The IP and PORT are the addresses used by the dpserver to download the one-click installation script.

[0117] Step a2: The proxy unit obtains the IP address of the physical machine.

[0118] For multiple network cards, the status obtained is the IP address of the UP network card. If there are multiple UP network cards, all of them are obtained and saved in array form.

[0119] Step a3: The agent unit obtains the host name of the physical machine.

[0120] Get the hostname of the physical host. The hostname is saved in string form.

[0121] Step a4: The agent unit obtains the details of the physical machine host.

[0122] Physical machine host details can include operating system and version, CPU architecture, number of CPUs, number of memories, storage capacity, etc.

[0123] Step a5: The proxy unit caches the acquired physical machine information locally.

[0124] Specifically, the physical machine information Cache can be stored in text form. Since the physical machine may be hot-expanded, in a more preferred implementation, the Cache information of the physical machine can be reviewed regularly every day. If there is a change, the change can be updated and the dpserver can be notified to update.

[0125] Step a6: The proxy unit establishes a connection with the dpserver via the built-in address.

[0126] If the connection establishment fails, the retry mechanism is used to retry, and step a6 is repeated until the maximum number of retries is reached. If the connection establishment is successful, step a7 is entered.

[0127] Step a7, the agent unit uploads the collected physical host information to the dpserver, and transmits it through the built-in API interface. The interface contains a callback address, and the dpserver notifies the agent of the processing result after the processing is completed.

[0128] Step a8, dpserver receives the physical host information uploaded by the agent, and structures the received physical host information.

[0129] Step a9: dpserver creates a management record based on the received information.

[0130] Step a10: dpserver completes the physical host management operation.

[0131] In step a11, dpserver notifies the agent of the completion of management through the callback mechanism.

[0132] Step S402: Create a template library, which is used to manage atomic template fragments and multifunctional templates.

[0133] Specifically, step S402 may include:

[0134] Step S4021, configuring multiple atomic template fragments.

[0135] Step S4022, combining the atomic template fragments according to the functional requirements of the application to obtain multiple multifunctional templates.

[0136] Step S4023, creating a template library for managing atomic template fragments and multifunctional templates.

[0137] Step S403: receiving a deployment request of a target application.

[0138] Step S404: In response to the deployment request, deployment resource matching is performed to determine a target deployment node.

[0139] Specifically, step S404 may include:

[0140] Step S4041, determining the requested resource amount of the target application.

[0141] Step S4042: When the requested resource amount is not greater than the total resource amount, it is determined that the initial matching is successful.

[0142] In some optional implementations, an initial match may be performed on the requested resource amounts.

[0143] Specifically, the initial matching phase allocates initial resources to applications through preset rules or manual configuration. It mainly provides a basic resource configuration for applications based on the application requirements and available resources. An initial resource allocation plan needs to be determined based on the type, scale and performance requirements of the application, as well as the quantity and performance of available resources.

[0144] Suppose there are n application programs for which resources need to be allocated, and the total available resources are R. The storage quantity is usually sufficient. Assume that the storage does not exceed the limit, and the allocation of storage is not considered. Only the allocation of CPU and memory resources is done. Define the function f(i) to represent the resource requirements of application program i, where i is a positive integer. The resource requirements are usually related to the expected number of users and the expected number of concurrent connections. Suppose the expected number of user accesses is U and the expected number of concurrent connections is C. Then the total required number of CPU cores can be expressed as U / C, and the total required memory capacity can be expressed as U*C. So, f(i) = {U / C, U*C}.

[0145] And the total resource quantity R can be expressed in the following way:

[0146] Suppose the total available resources are R, and the number of managed physical machines is n, where n is a positive integer. Then the total available resources are

[0147] where rc j is the available CPU quantity of the j-th physical machine, and rm j is the available memory capacity of the j-th physical machine.

[0148] For the initial matching, when f(i) < R, the initial matching is successful, indicating that the resource requirements of application program i can be met.

[0149] Step S4043, correct the applied resource quantity.

[0150] In some optional implementation manners, during the actual matching process, the whole process is more complex. For f(i), a system occupancy resource reservation ratio S ∈ [0, 1] needs to be added. Specifically, the following corrected formula can be used to correct the applied resource quantity:

[0151] f(i) = {U / C*(1 + S), U*C*(1 + S)};

[0152] Furthermore, the following formula is used to calculate the difference value between the resource requirements and the allocated resources of each application program:

[0153] d(i) = f(i) - R / n;

[0154] If d(i) ≥ 0, the resource requirements of application program i have been met, and no resource preemption is needed.

[0155] If d(i) < 0, the resource requirements of application program i have not been met, and resource preemption is needed.

[0156] Step S4044: polling is performed based on the revised applied resource amount and the resource margins of the multiple resource nodes, and a resource node whose resource margin is greater than the revised applied resource amount is determined as a target deployment node.

[0157] In some optional implementations, the above step S404 further includes:

[0158] Step S4045, dynamically adjusting the optimization factor for correcting the applied resource amount, so as to dynamically correct the applied resource amount.

[0159] Specifically, a pre-configured resource preemption strategy may be used to dynamically adjust an optimization factor for correcting the amount of applied resources.

[0160] For resource preemption strategy, priority strategy is usually adopted. If the priority of an application is higher than that of other applications, its resource demand will be met first. The following formula can be used to calculate the optimization factor:

[0161]

[0162] The numerator represents the priority weight of application i, and the denominator is Represents the sum of the priority weights of all applications.

[0163] The differential value formula after adding the optimization factor is as follows: d(i) = f(i) - R*p(i);

[0164] If d(i) ≥ 0, the resource requirements of application i have been met and the application can be deployed.

[0165] If d(i)<0, the resource requirements of application i are not met and the priority needs to be further adjusted to meet its deployment needs.

[0166] Repeat the above process until the resources meet the needs of the application.

[0167] Step S405: perform image resource security audit on the deployment program file.

[0168] In some optional implementations, image security auditing is a key link in ensuring the security of containerized business applications. First, the establishment of a unified image repository provides a basic guarantee for image security. Through strict control of warehouse permissions, only authorized personnel can upload and modify images, effectively reducing the possibility of malicious attacks or misoperations. Secondly, the introduction of third-party image scanning tools can more comprehensively discover and fix potential security vulnerabilities. Before the image is uploaded to the warehouse, it must be scanned by this tool to ensure that no vulnerabilities exist. In addition, in order to further ensure the security of the image, the uploaded image should be digitally signed. The digital signature can verify the integrity and source of the image to ensure that it has not been tampered with. Finally, the deployment tool should perform digital signature verification after obtaining the image to ensure that the obtained image is consistent with expectations, thereby ensuring the safe and stable operation of the business application.

[0169] Step S406: distribute the deployment program file package of the target application to the target deployment node.

[0170] Step S407 , determining a target template corresponding to the target application from the pre-configured multiple multifunctional templates, where the target template is a pre-configured atomic template fragment or the target template includes multiple pre-configured atomic template fragments, and the atomic template fragment is used to represent the function definition of the application program.

[0171] Step S408: execute the target template according to the deployment program file package, and deploy the target application to the target deployment node.

[0172] Step S409: receiving the deployment result of the target application.

[0173] The success of the automated deployment task can be confirmed through health checks. If the health check passes, the application has been successfully deployed, and the deployment management unit records the success status of the task and feeds back the success status to the administrator. If the health check fails, the deployment management unit records the failure status of the task and the reason for the failure. The notification channel includes preset email or SMS notifications, which can send deployment failure messages to relevant administrators in a timely manner.

[0174] Better yet, the deployment management unit automatically records the current version information of the deployed application. This information plays an extremely important role in subsequent deployment and troubleshooting, and can improve the efficiency of tracing and rollback.

[0175] Figure 4 For other implementation details of the illustrated embodiment, please refer to the above Figure 2 The detailed implementation details of the illustrated embodiment will not be repeated here.

[0176] In this embodiment, a multi-tenant-oriented deployment device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0177] This embodiment provides a deployment device for multiple tenants, such as Figure 5 As shown, including:

[0178] Receiving module 501, used to receive a deployment request of a target application;

[0179] The node determination module 502 is used to respond to the deployment request, match the deployment resources, and determine the target deployment node;

[0180] A distribution module 503 is used to distribute the deployment program file package of the target application to the target deployment node;

[0181] A target determination module 504 is used to determine a target template corresponding to a target application from a plurality of pre-configured multi-functional templates, where the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, where the atomic template fragment is used to characterize a function definition of the application program;

[0182] A deployment module 505 is used to execute a target template according to a deployment program file package and deploy a target application to a target deployment node;

[0183] The result acquisition module 506 is used to receive the deployment result of the target application.

[0184] In an optional embodiment, the device further comprises:

[0185] The audit module is used to perform image resource security audit on the deployment program file before distributing the deployment program file package of the target application to the target deployment node.

[0186] In an optional implementation, the node determination module 502 includes:

[0187] Application quantity unit, used to determine the application resource quantity of the target application;

[0188] A first matching unit, configured to determine that the initial matching is successful when the amount of resources applied for is not greater than the total amount of resources;

[0189] A correction unit, used to correct the resource quantity applied for;

[0190] The polling matching unit is used to perform polling based on the revised applied resource amount and the resource margin of multiple resource nodes, and determine the resource node whose resource margin is greater than the revised applied resource amount among the multiple resource nodes as the target deployment node.

[0191] In an optional implementation, the node determination module 502 further includes:

[0192] The dynamic adjustment unit is used to dynamically adjust the optimization factor for correcting the applied resource amount, so as to dynamically correct the applied resource amount.

[0193] In an optional implementation, the method is applied to a deployment management unit; the device further includes:

[0194] An agent configuration module is used to install an agent unit on multiple resource nodes before receiving a deployment request of a target application, and the agent unit has an address of a deployment management unit built in it;

[0195] An information receiving module, used for receiving the physical machine host information of multiple resource nodes acquired by the agent unit to the deployment management unit;

[0196] The management module is used to create management records for multiple resource nodes based on the physical machine host information of the multiple resource nodes.

[0197] In an optional embodiment, the device further comprises:

[0198] The atomic template module is used to configure multiple atomic template fragments before receiving a deployment request of a target application;

[0199] The combined template module is used to combine atomic template fragments according to the functional requirements of the application to obtain multiple multifunctional templates;

[0200] Template library module, used to create template libraries for managing atomic template fragments and multi-purpose templates.

[0201] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0202] The multi-tenant deployment device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0203] The embodiment of the present invention also provides a computer device having the above Figure 5 A deployment setup for multi-tenancy is shown.

[0204] See also Figure 6 , Figure 6 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0205] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0206] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.

[0207] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0208] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0209] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0210] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0211] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0212] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A multi-tenant deployment method, characterized in that: The method comprises: Receive a deployment request from a target application; In response to the deployment request, performing deployment resource matching and determining a target deployment node; Distributing the deployment program file package of the target application to the target deployment node; Determining a target template corresponding to the target application from a plurality of preconfigured multifunctional templates, wherein the target template is a preconfigured atomic template fragment or the target template includes a plurality of preconfigured atomic template fragments, and the atomic template fragment is used to characterize a function definition of the application program; According to the deployment program file package, executing the target template, deploying the target application to the target deployment node; A deployment result of the target application is received.

2. The method according to claim 1, characterized in that Before distributing the deployment program file package of the target application to the target deployment node, the method further includes: Perform a mirror resource security audit on the deployment program file.

3. The method according to claim 1, characterized in that The step of matching deployment resources in response to the deployment request and determining a target deployment node includes: Determining the amount of resources requested for the target application; In the case where the applied resource amount is not greater than the total resource amount, the initial matching is determined to be successful; amending the resource quantity applied for; Polling is performed based on the revised applied resource amount and the resource margins of multiple resource nodes, and a resource node whose resource margin is greater than the revised applied resource amount among the multiple resource nodes is determined as the target deployment node.

4. The method according to claim 3, characterized in that The step of matching deployment resources and determining a target deployment node in response to the deployment request further includes: Dynamically adjust the optimization factor for correcting the applied resource amount to dynamically correct the applied resource amount.

5. The method according to claim 1, characterized in that The method is applied to a deployment management unit; Before receiving the deployment request of the target application, the method further includes: Installing agent units on multiple resource nodes, wherein the agent units have built-in addresses of deployment management units; Receiving the physical machine host information of the plurality of resource nodes acquired by the agent unit to the deployment management unit; Based on the physical host information of multiple resource nodes, create management records for multiple resource nodes.

6. The method according to claim 1, characterized in that Before receiving the deployment request of the target application, the method further includes: Configure multiple atom template fragments; According to the functional requirements of the application, the atomic template fragments are combined to obtain multiple multifunctional templates; A template library for managing the atomic template fragments and the multifunctional template is created.

7. A deployment device for multiple tenants, characterized in that: The device comprises: A receiving module, used for receiving a deployment request of a target application; A node determination module, used to respond to the deployment request, perform deployment resource matching, and determine a target deployment node; A distribution module, used to distribute the deployment program file package of the target application to the target deployment node; a target determination module, configured to determine a target template corresponding to the target application from a plurality of pre-configured multi-functional templates, wherein the target template is a pre-configured atomic template fragment or the target template includes a plurality of pre-configured atomic template fragments, and the atomic template fragment is used to characterize a function definition of the application program; A deployment module, configured to execute the target template according to the deployment program file package, and deploy the target application to a target deployment node; The result acquisition module is used to receive the deployment result of the target application.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the multi-tenant deployment method described in any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the multi-tenant-oriented deployment method according to any one of claims 1 to 6.

10. A computer program product, characterized in that It comprises computer instructions, and the computer instructions are used to enable a computer to execute the multi-tenant-oriented deployment method according to any one of claims 1 to 6.