Configuration management method of configuration management tool
By uniformly managing keys and configuration data in the configuration management tool, and adopting a hierarchical management structure and permission isolation strategy, the complex problems of key management in the existing technology are solved, and system integration and security are improved.
Patent Information
- Application Number
- CN202510460497.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-14
AI Technical Summary
The existing configuration management tools lack native support for keys, resulting in complex management of sensitive data, difficult system integration, and fragmented configuration management processes.
A configuration management method is adopted, by uniformly managing keys and configuration data, and a hierarchical configuration management structure is adopted to finely divide the keys and configuration data, and set permission isolation policies between different management levels.
It reduces the complexity of system integration, avoids the risk of key exposure, improves configuration management efficiency and system security, and meets the application needs of complex business scenarios.
Smart Images

Figure CN119987902A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of configuration management tools, and in particular to a configuration management method of a configuration management tool. Background Art
[0002] At present, the common distributed configuration management tools on the market can provide basic functions such as configuration storage and dynamic loading for configuration management tools, and provide configuration tool support for application objects. Although the existing configuration management tools have improved the efficiency of configuration management to a certain extent, the existing configuration management tools lack native support for keys, resulting in sensitive data requiring configuration management tools to be managed with additional tools, which increases the complexity and integration difficulty of the system and causes the management process of system configuration to be fragmented. Summary of the invention
[0003] The technical problem to be solved by the present invention is: a configuration management method for a configuration management tool, so as to solve the problem that the existing configuration management tools lack the management of keys, which leads to complex system integration.
[0004] In order to solve the above technical problems, the technical solution adopted by the present invention is: a configuration management method of a configuration management tool, the configuration management tool is used to manage configuration data and keys, comprising the following steps: S1. Dividing the configuration data according to a plurality of predefined management levels to form a hierarchical configuration management structure; S2. The variables of the configuration data and / or the key support referencing other keys and / or other variables; performing nested parsing on the other keys and / or other variables referenced by the configuration data or the key according to a preset priority order of the hierarchical configuration management structure; S3. Within the same management level, the configuration data and the key adopt a unified management mechanism; and the plurality of management levels are respectively provided with permission isolation strategies to limit the access rights of the management levels.
[0005] The beneficial effects of the present invention are as follows: the configuration management method provided by the present invention manages keys and configuration data in a unified manner, avoids the system from using multiple sets of management tools, reduces the complexity of system integration, and avoids the exposure of keys due to multiple sets of system calls during development or operation and maintenance. The configuration management method not only improves the configuration management efficiency, but also improves the system security; in addition, the configuration management method divides the configuration data and keys into fine hierarchical levels, so that the configuration management method can meet the application requirements of complex business scenarios; in addition, the different management levels of the configuration management method adopt a permission isolation strategy for permission isolation to ensure the security of configuration data and keys. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Figure 1 This is a flowchart of the configuration management method of the configuration management tool described in the present invention. DETAILED DESCRIPTION
[0007] In order to explain the technical content, achieved objectives and effects of the present invention in detail, the following is an explanation in combination with the implementation modes and the accompanying drawings.
[0008] Please refer to Figure 1 The present invention provides a configuration management method of a configuration management tool, wherein the configuration management tool is used to manage configuration data and keys, comprising the following steps: S1. Dividing the configuration data according to a plurality of predefined management levels to form a hierarchical configuration management structure; S2. The variables of the configuration data and / or the key support referencing other keys and / or other variables; performing nested parsing on the other keys and / or other variables referenced by the configuration data or the key according to a preset priority order of the hierarchical configuration management structure; S3. Within the same management level, the configuration data and the key adopt a unified management mechanism; and the plurality of management levels are respectively provided with permission isolation strategies to limit the access rights of the management levels.
[0009] From the above description, it can be seen that the beneficial effects of the present invention are: the configuration management method provided by the present invention manages keys and configuration data in a unified manner, avoids the system using multiple sets of management tools, reduces the complexity of system integration, and avoids the exposure of keys due to the call of multiple sets of tools during development or operation and maintenance. The configuration management method not only improves the configuration management efficiency, but also improves the system security; in addition, the configuration management method performs a refined hierarchical division of configuration data and keys, so that the configuration management method can meet the application requirements of complex business scenarios; in addition, different management levels of the configuration management method adopt a permission isolation strategy for permission isolation to ensure the security of configuration data and keys.
[0010] Furthermore, the multiple management levels include: namespace global configuration, cluster global configuration, environment global configuration and application private configuration.
[0011] From the above description, it can be seen that configuration data and keys can be divided into four management levels, each management level has independent management configuration, and the variables of the configuration data of one management level can reference the variables of the configuration data in the other three management levels, so as to realize multi-level nesting and flexible combination of configuration data, form a hierarchical configuration management structure, improve the flexibility of configuration management, and meet the configuration management needs of different management levels.
[0012] Furthermore, in step S2, the variables of the configuration data and / or the key support referencing other keys and / or other variables, including: The variables of the configuration data and / or the key reference the other variables through a first tag format; the variables of the configuration data and / or the key reference the other key through a second tag format; the other variables and the other key are both tag variables of the configuration data.
[0013] As can be seen from the above description, the configuration management method enables variables or keys of configuration data to reference other variables or keys by presetting a tag format, and distinguishes the types of tag variables referenced by the tag format.
[0014] Furthermore, in step S2, according to the preset priority order of the hierarchical configuration management structure, nested parsing is performed on the configuration data or the other keys and / or the other variables referenced by the key, including the following steps: S21, matching the tag variable in the configuration data by using a regular expression, and identifying the tag variable as the other key or the other variable; S22, if the tag variable is matched, searching for a variable value or a key value corresponding to the tag variable according to a preset priority order of the hierarchical configuration management structure; S23, replacing the mark variable in the configuration data with the variable value or the key value; S24, recursively searching whether there are other tag variables in the configuration data; if there are other tag variables in the configuration data, repeating steps S21 to S23 until all tag variables in the configuration data are parsed and the regular expression cannot match any new tag variables.
[0015] From the above description, it can be seen that the variables or keys of the configuration data of the configuration management method can reference other variables or other keys, and a multi-level dynamic parsing mechanism is adopted when parsing the configuration data or keys. The order of nested parsing is based on the preset priority order of the hierarchical configuration management structure. The configuration management method can ensure that the configuration data or key parsing logic is clear and does not conflict.
[0016] Furthermore, in the step S3, within the same management level, the key and the configuration data adopt a unified management mechanism including: encrypting and storing the value of the key.
[0017] It can be seen from the above description that the configuration management method can ensure the security of the key.
[0018] Further, the configuration data references a key of the secret key; When the variable of the configuration data references the key of the secret key and the configuration data is acquired by the application object, the secret key is decrypted to acquire the value of the secret key.
[0019] From the above description, it can be seen that the content of the key is parsed only when the configuration data is obtained by the application object.
[0020] Furthermore, when the variables of the configuration data reference other variables or other keys, and the other variables or the other keys are changed, the configuration data is modified according to the changed other variables or other keys.
[0021] It can be seen from the above description that the configuration management method can realize that the configuration data supports dynamic variable references, and can realize configuration parsing and dynamic changes in complex scenarios.
[0022] Furthermore, the management mechanism includes at least one or more of a default value of the management level, a priority of the management level, and an overlay logic of the management level.
[0023] From the above description, it can be seen that each management level can set independent default values, priorities and override logic to enable the configuration management method to adapt to complex business scenarios.
[0024] Furthermore, the method further comprises the following steps: performing a similarity comparison on all configuration data, and defining a configuration template according to the similarity comparison result; The same or similar configuration data is stored based on the configuration template.
[0025] It can be seen from the above description that the configuration management method can abstract repeated or similar configuration data into reusable configuration templates, and apply the configuration templates to multiple environments or applications to reduce configuration redundancy and improve maintenance efficiency.
[0026] Furthermore, the method further includes the following steps: monitoring configuration change events, and when the configuration change event occurs, pushing the corresponding configuration data to the target application object.
[0027] From the above description, it can be seen that the configuration management method supports dynamic loading and change notification. After a configuration change event occurs in the configuration data, the system automatically pushes the configuration data with the change event to the relevant applications without manual restart or redeployment. The configuration management method has high configuration management efficiency.
[0028] Embodiment 1 Please refer to Figure 1 Embodiment 1 of the present invention provides a configuration management method of a configuration management tool, wherein the configuration management tool is used to manage configuration data and keys, and comprises the following steps: S1. Dividing the configuration data according to a plurality of predefined management levels to form a hierarchical configuration management structure; S2. The variables of the configuration data and / or the key support referencing other keys and / or other variables; performing nested parsing on the other keys and / or other variables referenced by the configuration data or the key according to a preset priority order of the hierarchical configuration management structure; S3. Within the same management level, the configuration data and the key adopt a unified management mechanism; and the plurality of management levels are respectively provided with permission isolation strategies to limit the access rights of the management levels.
[0029] Existing configuration management tools (such as Spring Cloud Config, Consul, etcd, etc.) lack native support for keys. The management of sensitive data (such as API keys, passwords, etc.) usually requires the cooperation of additional tools (such as Vault or KMS), which makes it impossible to manage keys and configuration data in a unified manner, causing confusion in management and use during development and operation and maintenance. In addition, calling multiple sets of tools can easily lead to key exposure, making the existing system low in integration and security. At the same time, existing configuration management tools only support single-layer parsing and cannot implement multi-level nested references of environment variables, which limits the flexibility of configuration data expression. In complex configuration scenarios, it is impossible to dynamically generate complete configuration information by nesting references to other variables or keys.
[0030] Different from existing configuration management tools, the configuration management method provided in this embodiment can provide native support for keys and uniformly manage keys and configuration data. The configuration management tool using this method supports multi-level nested references of variables. The parsing capability of the configuration management tool is improved through multi-level nested references of variables and a multi-level nested parsing mechanism of variables, thereby solving the problem of separation of key and configuration data management.
[0031] Specifically, the variables or keys of the configuration management tool in this embodiment support referencing other variables or other keys, so that keys and environment variables can be embedded in the configuration data through multi-level references, so that the environment variables and keys can be obtained and parsed when the configuration data is called and parsed, and the parsing of the configuration data or keys is strictly performed in accordance with the preset priority order of the hierarchical configuration management structure to ensure that the parsing logic is clear and there is no conflict.
[0032] In addition, the configuration management method provided in this embodiment can divide the configuration data and / or keys according to multiple predefined management levels; on the one hand, each management level sets up an independent management mechanism according to management needs, which can improve the flexibility of configuration management; on the other hand, the various management levels allow users to flexibly combine according to business needs to form a hierarchical configuration management structure.
[0033] It is easy to understand that since the variables or keys of the configuration management tool of the configuration management method of this embodiment support the application of other variables or keys, the configuration data or keys in one management level can use the configuration data in other management levels as other variables, and / or use the keys in other management levels as other keys, thereby realizing flexible combination and multi-level nested reference between configuration data and / or keys belonging to different management levels.
[0034] In step S2 of this embodiment, the variables of the configuration data and / or the key support referencing other keys and / or other variables, including: The variables of the configuration data and / or the key reference the other variables through a first tag format; the variables of the configuration data and / or the key reference the other key through a second tag format; the other variables and the other key are both tag variables of the configuration data.
[0035] Accordingly, in step S2 of this embodiment, nested parsing is performed on the configuration data or the other keys and / or the other variables referenced by the key according to the preset priority order of the hierarchical configuration management structure, including the following steps: S21, matching the tag variable in the configuration data by using a regular expression, and identifying the tag variable as the other key or the other variable; S22, if the tag variable is matched, searching for a variable value or a key value corresponding to the tag variable according to a preset priority order of the hierarchical configuration management structure; S23, replacing the mark variable in the configuration data with the variable value or the key value; S24, recursively searching whether there are other tag variables in the configuration data; if there are other tag variables in the configuration data, repeating steps S21 to S23 until all tag variables in the configuration data are parsed and the regular expression cannot match any new tag variables.
[0036] In this embodiment, when the variables of the configuration data reference other variables or other keys, and the other variables or the other keys are changed, the configuration data is modified according to the changed other variables or other keys.
[0037] As an example: the configuration data and / or key references the other variables through the first tag format ${tag}, and the configuration data and / or key second tag format *{tag} references the other keys; the value of a configuration data variable db_connection is set to: server=${mysql_host};user_id=root;database=db1;password=*{mysql_pwd}; the variable db_connection references the other variable mysql_host through the first tag format, and references the other key mysql_pwd through the second tag format. This method of implementing multi-level variable references through different tag formats can facilitate unified management, and it is convenient to distinguish the tag variables as variables or keys according to the tag format. According to the configuration management method provided in this embodiment, when the variable mysql_host changes, as long as the variable mysql_host is modified, all other variables that reference mysql_host will be modified accordingly, such as: the variable db_connection will change its sub-variable server=${mysql_host}, while the other sub-variables of the variable db_connection remain unchanged, thereby realizing the dynamic change of configuration data.
[0038] The configuration management method provided in this embodiment can support nested parsing, significantly improving the dynamic parsing capability and configuration expression capability of the configuration management tool.
[0039] In order to ensure the security of the key, in step S3 of this embodiment, within the same management level, the key and the configuration data adopt a unified management mechanism including: encrypting and storing the value of the key.
[0040] In detail, the configuration data references the key of the key; when the variable of the configuration data references the key of the key and the configuration data is obtained by the application object, the key is decrypted to obtain the value of the key.
[0041] In this embodiment, when the configuration data is applied to the key, only the key of the key is saved in the configuration data, and the value of the key is parsed only when the configuration data is acquired by the application object.
[0042] As an example: the key *{mysql_pwd} is referenced in the variable of the configuration data. The variable of the configuration data only contains the key value of the key. The variable of the configuration data is parsed only in the application object, and the referenced key *{mysql_pwd} is securely decrypted and the real value of the key is returned. The security verification is passed through the real value of the key.
[0043] A system that applies the configuration management method provided in this embodiment does not need to use multiple sets of tools to manage configuration data and keys separately. Instead, configuration data and keys are managed uniformly through configuration management tools. This can reduce the complexity of system integration, reduce the risk of exposing keys during development or operation and maintenance, and improve the management efficiency and security of the system that applies the configuration management method.
[0044] Specifically, in this embodiment, the multiple management levels include: namespace global configuration, cluster global configuration, environment global configuration and application private configuration.
[0045] In detail, this embodiment sets four predefined management levels for the configuration management tool according to the role of the configuration and the application object; among them, the namespace global configuration is the common configuration shared in the same namespace; the cluster global configuration is the configuration that is effective for all nodes under the same cluster; the environment global configuration is the environment-level configuration for the development, test, and production environments; and the application private configuration is the configuration specific to a single application object.
[0046] In this embodiment, within the same management level, the configuration data and the key adopt a unified management mechanism; wherein the management mechanism includes at least one or more of the default value of the management level, the priority of the management level, and the coverage logic of the management level.
[0047] In order to further improve the security of the configuration management method, the configuration management method also sets permission isolation strategies for the multiple management levels to limit the access rights of the management levels. By limiting the access rights of the management levels, the access and management of the configuration data are strictly restricted to ensure the security of the configuration data and keys.
[0048] In this embodiment, the preset priority order of the hierarchical configuration management structure is from low to high: namespace global configuration, cluster global configuration, environment global configuration and application private configuration.
[0049] For example, three configuration data are divided into namespace global configuration, cluster global configuration 1 and cluster global configuration 2. A variable db_user=root is defined in the namespace global configuration. Cluster global configuration 1 and cluster global configuration 1 define variables db_user=user1 and db_user=user2, respectively. Because the priority of cluster global configuration is higher than that of namespace global configuration, cluster global configuration 1 and cluster global configuration 2 use user1 and user2 as variable values, respectively, during parsing. If other configuration data in the cluster global configuration does not match the variable db_user in the cluster global configuration, the default value root provided by the variable db_user matched in the namespace global configuration is used.
[0050] Since the configuration management method provided in this embodiment manages keys and configuration data in a unified manner and divides configuration data according to a plurality of predefined management levels, it may cause duplicate configuration data to appear in the configuration management tool. In order to reduce the possibility of duplicate configuration data appearing in the configuration management tool, the configuration management method further includes the following steps: performing a similarity comparison on all configuration data, defining a configuration template according to the similarity comparison result; and storing the same or similar configuration data based on the configuration template.
[0051] The configuration management method provided in this embodiment can store repeated or similar configuration data as a reusable configuration template, and the configuration template supports parameterized configuration references.
[0052] As an example, the connection configuration of a database can configure its connection string or service endpoint to form the following database connection configuration template: "DbProvider": { "DefaultConnection": "Mysql" }, "ConnectionStrings": { "DefaultConnection": "${mysql_conn}", "LocalizationConnection": "${i18n_conn}" } When connecting to the database through the above connection configuration template in different application objects or environments, you only need to specify the variable value for the connection configuration template.
[0053] The configuration management method provided in this embodiment can significantly reduce duplicate configuration data, improve the reusability of configuration data, reduce configuration data redundancy, and improve the maintenance efficiency of configuration management tools.
[0054] In this embodiment, the configuration management method further includes the steps of: monitoring configuration change events, and when the configuration change event occurs, pushing the corresponding configuration data to the target application object. The configuration management tool supports dynamic loading and real-time change notification. After the user modifies the configuration, the system automatically pushes the changes to the relevant application objects without manual restart or redeployment. The configuration management tool has high real-time performance, which improves the agility and availability of the system.
[0055] In summary, the configuration management method provided by the present invention manages keys and configuration data in a unified manner, avoids the system from using multiple sets of management tools, reduces the complexity of system integration, and avoids the exposure of keys due to the call of multiple sets of tools during development or operation and maintenance. The configuration management method not only improves the efficiency of configuration management, but also improves the security of the system; in addition, the configuration management method performs refined hierarchical division of configuration data and keys, so that the configuration management method can meet the application requirements of complex business scenarios; in addition, different management levels of the configuration management method adopt permission isolation strategies for permission isolation to ensure the security of configuration data and keys.
[0056] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent transformations made using the contents of the present invention's specification and drawings, or directly or indirectly applied in related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A configuration management method for a configuration management tool, characterized in that: The configuration management tool is used to manage configuration data and keys, including the following steps: S1. Dividing the configuration data according to a plurality of predefined management levels to form a hierarchical configuration management structure; S2. The variables of the configuration data and / or the key support referencing other keys and / or other variables; performing nested parsing on the other keys and / or other variables referenced by the configuration data or the key according to a preset priority order of the hierarchical configuration management structure; S3. Within the same management level, the configuration data and the key adopt a unified management mechanism; and the plurality of management levels are respectively provided with permission isolation strategies to limit the access rights of the management levels.
2. The configuration management method according to claim 1, characterized in that: The multiple management levels include: namespace global configuration, cluster global configuration, environment global configuration and application private configuration.
3. The configuration management method according to claim 1, characterized in that: In step S2, the variables of the configuration data and / or the keys support referencing other keys and / or other variables, including: The variables of the configuration data and / or the key reference the other variables through a first tag format; the variables of the configuration data and / or the key reference the other key through a second tag format; the other variables and the other key are both tag variables of the configuration data.
4. The configuration management method according to claim 3, characterized in that: In step S2, according to the preset priority order of the hierarchical configuration management structure, nested parsing is performed on the configuration data or other keys and / or other variables referenced by the key, including the following steps: S21, matching the tag variable in the configuration data by using a regular expression, and identifying the tag variable as the other key or the other variable; S22, if the tag variable is matched, searching for a variable value or a key value corresponding to the tag variable according to a preset priority order of the hierarchical configuration management structure; S23, replacing the mark variable in the configuration data with the variable value or the key value; S24, recursively searching whether there are other tag variables in the configuration data; if there are other tag variables in the configuration data, repeating steps S21 to S23 until all tag variables in the configuration data are parsed and the regular expression cannot match any new tag variables.
5. The configuration management method according to claim 1, characterized in that: In the step S3, within the same management level, the key and the configuration data adopt a unified management mechanism including: encrypting and storing the value of the key.
6. The configuration management method according to claim 5, characterized in that: The configuration data references a key of the secret key; When the variable of the configuration data references the key of the secret key and the configuration data is acquired by the application object, the secret key is decrypted to acquire the value of the secret key.
7. The configuration management method according to claim 1, characterized in that: When a variable of the configuration data references other variables or other keys, and the other variables or the other keys are changed, the configuration data is modified according to the changed other variables or other keys.
8. The configuration management method according to claim 1, characterized in that: The management mechanism includes at least one or more of a default value of the management level, a priority of the management level, and an overlay logic of the management level.
9. The configuration management method according to claim 1, characterized in that: The following steps are also included: Perform similarity comparison on all configuration data and define configuration templates based on the similarity comparison results; The same or similar configuration data is stored based on the configuration template.
10. The configuration management method according to claim 1, characterized in that: The following steps are also included: Monitor configuration change events, and when the configuration change event occurs, push the corresponding configuration data to the target application object.
Citation Information
Patent Citations
Configuration data management method and system
CN110362358A
Multi-layer key configuration method and device
CN115766086A
Regular expression-based data analysis normalization mechanism
CN116070616A
Database data encryption method and device based on multiple granularities
CN117992991A
Custom Mock platform and network request simulation processing method based on same
CN119473273A