Method for mounting / unloading network file system by container, container platform and medium
By allocating the target container according to the container security level and mounting the network file system inside the container, the problems of platform security and performance when the security needs of container application scenarios are high in the prior art are solved, and higher security and performance are achieved.
Patent Information
- Application Number
- CN202311501548.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-10
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, when the security demand for container application scenarios is high, file data encryption is carried out at the running node and may be tampered with by other programs, resulting in poor platform security and affecting the read and write efficiency of data in the container and reducing platform performance.
By receiving the running container request sent by the user terminal, the corresponding target container is allocated according to the container security level, and the mount of the network file system and the target container is completed according to the mount policy of the target container. For containers with high security levels, mount them inside the container to avoid encrypting file data at the running node.
It improves the security and performance of the platform, avoids the risk of other programs tampering with file data, saves encryption steps, and improves the read and write efficiency of data in the container.
Smart Images

Figure CN119987936A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a method for mounting / unmounting a network file system in a container, a container platform, and a medium. Background Art
[0002] Generally, cloud platforms have a storage-computing separation architecture, and containers can be used to reference external storage resources to achieve storage persistence and storage sharing. External storage resources can be various cloud hard disks and network file systems.
[0003] Containerization is one of the main technologies in the field of cloud computing, which is to encapsulate applications into containers to achieve isolation and scheduling. The container platform is responsible for processing user requests, parsing the container's requirements for computing, storage, and network, and allocating corresponding running nodes to the container. The container engine on the node can achieve the above requirements and start the container. In the prior art, when the container mounts a network file system, the container platform will first mount the network file system to the system directory of the running node. If the container application scenario has high security requirements, the specified file data will be encrypted, and then the corresponding container will be allocated for this mounting on the running node, and finally the file data will be imported into the container to achieve the mounting of the container and the network file system. Cloud platforms generally need to be compatible with different application scenarios such as high performance and high security. However, when the container application scenario has high security requirements, since the encryption of file data is performed on the running node, it may be tampered with or affected by other programs, the platform security is poor, and the import of encrypted file data affects the read and write efficiency of data in the container, reducing the platform performance.
[0004] Therefore, a solution for mounting / unmounting network file systems in containers is needed that can improve platform security and performance. Summary of the invention
[0005] The present application provides a method for mounting / unmounting a network file system in a container, a container platform, and a medium, so as to solve the technical problem that the existing method for mounting a network file system in a container reduces the security and performance of the platform.
[0006] In a first aspect, the present application provides a method for mounting a network file system in a container, comprising:
[0007] Receive a container operation request sent by a user terminal, where the container operation request includes a container security level, an address of a network file system to be mounted, and a sharing protocol corresponding to the network file system;
[0008] Determine a container running node corresponding to the container running request, wherein the container running node includes a network card connected to a storage network;
[0009] Determine, according to the container security level, a target container corresponding to the container running node of the container running request;
[0010] On the container running node, the network file system and the target container are mounted according to the mounting policy corresponding to the target container.
[0011] In a possible implementation, the container operation request further includes the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory; when the container security level is a normal level, the target container is a normal container, and accordingly, the node running the container completes the mounting of the network file system and the target container according to the mount policy corresponding to the target container, specifically including:
[0012] According to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, the mounting of the network file system and the container running node is completed;
[0013] Initialize a first operating environment of the common container on the container operating node, and establish the mount target directory in the first operating environment, where the first operating environment is a container host environment;
[0014] On the container running node, establishing a mapping relationship between the shared directory and the mount target directory;
[0015] On the container running node, calling the container engine to start the common container, and completing the mounting of the network file system and the common container;
[0016] The shared directory is a directory of files specified by the user in the network file system, and the mount target directory is a directory of files specified by the user in the first operating environment.
[0017] In a possible implementation, the step of completing the mounting of the network file system and the container running node according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system specifically includes:
[0018] Determine, according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, whether the network file system under the sharing protocol has been mounted under the first system directory of the container running node;
[0019] If not, mounting the network file system to the first system directory according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system;
[0020] If so, determine whether the shared directory exists under the mount point of the first system directory. If not, create the shared directory under the mount point of the first system directory.
[0021] In a possible implementation, the container operation request further includes mounting a target directory. When the container security level is a high security level, the target container is a high security container. Accordingly, the container operation node completes the mounting of the network file system and the target container according to the mounting policy corresponding to the target container, specifically including:
[0022] Initialize the second operating environment of the high-security container on the container operating node, and establish the mount target directory in the second operating environment, where the second operating environment is the internal environment of the container;
[0023] On the container running node, generating a corresponding virtual network card according to the network card connected to the storage network, and adding the virtual network card to the second running environment;
[0024] Writing the virtual network card, the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory into a target file of the second operating environment, where the target file corresponds to the container operation request;
[0025] Calling a container engine to start the high-security container, so that when the container engine reads the target file in the second operating environment, it uses the virtual network card to connect to the network, and mounts the network file system to the second system directory of the second operating environment according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system in the second operating environment; establishing the shared directory under the mount point of the second system directory, and establishing a mapping relationship between the shared directory and the mount target directory, so as to complete the mounting of the network file system and the high-security container;
[0026] The shared directory is a directory of files specified by the user in the network file system, and the mount target directory is a directory of files specified by the user in the second operating environment.
[0027] In a second aspect, the present application provides a method for unloading a network file system from a container, comprising:
[0028] receiving a container termination request sent by a user terminal, wherein the container termination request includes target container information and a container security level;
[0029] Determine the target container to be uninstalled and the corresponding network file system according to the target container information;
[0030] If the container security level of the target container is a normal level, a normal container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system;
[0031] If the container security level of the target container is a high security level, a high security container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system.
[0032] In a possible implementation manner, the end container request further includes a shared directory and a mount target directory, and the common container uninstallation strategy is adopted to complete the uninstallation of the container to be uninstalled and the network file system, specifically including:
[0033] Determine the container running node where the target container is located, and call the container engine on the container running node to stop the target container;
[0034] Deleting the mount target directory in the first running environment of the target container and the mapping relationship between the shared directory and the mount target directory on the container running node;
[0035] Unmounting the shared directory at the mount point of the first system directory of the container running node;
[0036] Among them, the first operating environment is a container host environment, the shared directory is a directory of the file specified by the user in the network file system, and the mount target directory is a directory of the file specified by the user in the first operating environment.
[0037] In a possible implementation manner, the end container request further includes a shared directory and a mount target directory, and the high-security container uninstallation strategy is adopted to complete the uninstallation of the container to be uninstalled and the network file system, specifically including:
[0038] Determine a container running node where the target container is located and a second running environment corresponding to the target container;
[0039] Calling a container engine on the container running node to stop the target container, so that when the container engine reads the target file in the second running environment, it deletes the mapping relationship between the shared directory and the mount target directory, and unmounts the shared directory under the mount point of the second system directory of the second running environment;
[0040] Deleting the mount target directory in the second operating environment of the target container and the virtual network card corresponding to the target container on the container operating node;
[0041] Among them, the second operating environment is the internal environment of the container, the shared directory is the directory of the file specified by the user in the network file system, the mount target directory is the directory of the file specified by the user in the second operating environment, the virtual network card is generated according to the network card connected to the storage network when the target container is mounted, and the target file is generated according to the virtual network card when the target container is mounted, the address of the network file system, the sharing protocol corresponding to the network file system, the shared directory and the mount target directory.
[0042] In a possible implementation manner, the container termination request further includes a sharing protocol corresponding to the network file system, and after the target container and the network file system are uninstalled, the following step further is included:
[0043] Determine whether there is a target common container for mounting the network file system on the container running node according to the address of the network file system to be unloaded and the sharing protocol corresponding to the network file system;
[0044] If not, the network file system is uninstalled under the first system directory of the container running node.
[0045] In a second aspect, the present application provides a container platform, including:
[0046] A first receiving module is configured to receive a container operation request sent by a user terminal, wherein the container operation request includes a container security level;
[0047] The first processing module is used to determine the container running node corresponding to the running container request, the container running node includes a network card connected to the storage network; determine the target container corresponding to the running container request at the container running node according to the container security level; and complete the mounting of the network file system and the target container at the container running node according to the mounting policy corresponding to the target container.
[0048] In a third aspect, the present application provides another container platform, including:
[0049] A second receiving module is used to receive a container termination request sent by a user terminal, wherein the container termination request includes target container information, a container security level, and an address of a network file system to be unloaded;
[0050] The second processing module is used to determine the target container to be unloaded according to the target container information; if the container security level of the target container is a normal level, a normal container unloading strategy is adopted to complete the unloading of the target container and the network file system; if the container security level of the target container is a high security level, a high security container unloading strategy is adopted to complete the unloading of the target container and the network file system.
[0051] In a fourth aspect, the present application provides another container platform, comprising: a processor, and a memory communicatively connected to the processor;
[0052] The memory stores computer-executable instructions;
[0053] The processor executes the computer-executable instructions stored in the memory to implement the above method.
[0054] In a fifth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to implement the above-mentioned method when executed by a processor.
[0055] In a sixth aspect, the present application provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0056] The method, container platform and medium for mounting / unmounting a network file system in a container provided by the present application can receive a running container request sent by a user terminal, and the running container request includes a container security level; determine the container running node corresponding to the running container request, and the container running node includes a network card connected to the storage network; according to the container security level, determine the target container corresponding to the running container request at the container running node; at the container running node, according to the mounting policy corresponding to the target container, complete the mounting of the network file system and the target container. After receiving the running container request, the method of the present application can allocate the corresponding target container according to the container security level in the running container request, and complete the mounting of the network file system and the target container according to the mounting policy corresponding to the target container, that is, first allocate the container and then complete the mounting. Through such a setting, when the network file system and the container are mounted, different containers and mounting policies can be allocated according to different security levels. When the security requirements of the container application scenario are high, a high-security container with a higher security level can be allocated, and mounted with the mounting policy corresponding to the high-security container. There is no need to encrypt the specified file at the running node, which avoids tampering or influence of other programs and improves the security of the platform. Furthermore, when mounting with the mounting policy corresponding to the high-security container, there is no need to encrypt the file, which saves the extra encryption step and also avoids the impact of the import of encrypted file data on the data reading and writing efficiency in the container, thereby improving the platform performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0058] Figure 1A flowchart of a method for mounting a network file system on a container according to an embodiment of the present application;
[0059] Figure 2 A flowchart of a method for unloading a network file system from a container according to an embodiment of the present application;
[0060] Figure 3 This is a schematic diagram of the structure of a container platform according to an embodiment of the present application;
[0061] Figure 4 This is a schematic structural diagram of a container platform according to another embodiment of the present application;
[0062] Figure 5 This is a schematic structural diagram of a container platform according to another embodiment of the present application.
[0063] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0064] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0065] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0066] It should also be noted that the method for mounting / unmounting a network file system by a container, the container platform, and the medium of the present application can be used in the field of data processing, and can also be used in any field other than the field of data processing, such as the field of containerization technology, etc. The application field of the method for mounting / unmounting a network file system by a container, the container platform, and the medium of the present application is not limited.
[0067] First, the terms involved in this application are explained:
[0068] The Network File System (NFS) is a network abstraction on top of the file system. It is one of the file systems supported by FreeBSD. NFS allows a system to share directories and files with others on the network. By using NFS, users and programs can access files on the remote system just like accessing local files.
[0069] Mounting refers to the process by which the operating system makes computer files and directories on a storage device (such as a hard disk, CD-ROM, or shared resource) accessible to users through the computer's file system.
[0070] Unmount (umount), corresponding to mount (mount), refers to unmounting devices, mount points and other file systems under the operating system. It can unmount the specified device or file system from the system and release related resources.
[0071] A container is a software package that can contain an application and all its dependencies. Inside the container, the application runs in an isolated environment, which is usually provided by a container engine. Containers do not have a complete operating system to manage resources and processes. They use the kernel of the host system and package the application and its dependencies together to run as a container.
[0072] Based on this technical problem, the inventive concept of this application is: how to provide a method for mounting / unmounting a network file system in a container that can improve platform security and performance.
[0073] Specifically, a container operation request sent by a user terminal can be received, and the container operation request includes a container security level; the container operation node corresponding to the container operation request is determined, and the container operation node includes a network card connected to the storage network; according to the container security level, the target container corresponding to the container operation request in the container operation node is determined; at the container operation node, according to the mount policy corresponding to the target container, the network file system and the target container are mounted. The method of the present application, after receiving the container operation request, can allocate the corresponding target container according to the container security level in the container operation request, and complete the mounting of the network file system and the target container according to the mount policy corresponding to the target container, that is, first allocate the container and then complete the mounting. Through such a setting, when the network file system and the container are mounted, different containers and mount policies can be allocated according to different security levels. When the security requirements of the container application scenario are high, a high-security container with a higher security level can be allocated, and mounted with the mount policy corresponding to the high-security container. There is no need to encrypt the specified file at the running node, which avoids tampering or influence by other programs and improves the security of the platform. Furthermore, when mounting with the mounting policy corresponding to the high-security container, there is no need to encrypt the file, which saves the extra encryption step and also avoids the impact of the import of encrypted file data on the data reading and writing efficiency in the container, thereby improving the platform performance.
[0074] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0075] Embodiment 1
[0076] Figure 1 This is a flow chart of a method for mounting a network file system on a container according to an embodiment of the present application. This embodiment uses a container platform as an execution subject to illustrate the method for mounting a network file system on the container. Figure 1 As shown, the method for mounting a network file system by a container may include the following steps:
[0077] S101: Receive a container execution request sent by a user terminal, where the container execution request includes a container security level.
[0078] In this embodiment, the container platform may be a cloud server including multiple server hosts.
[0079] S102: Determine a container running node corresponding to the container running request, where the container running node includes a network card connected to a storage network.
[0080] In this embodiment, since some steps in the container mounting and running process require connecting to the network, the container running node needs to include a network card connected to the storage network to ensure smooth network access.
[0081] In this embodiment, the container running node may be a host where the container is running, and one container running node may accommodate the running of multiple containers.
[0082] In this embodiment, the container running node corresponding to the container running request is determined, that is, a corresponding running node, that is, a container host, is allocated to the container.
[0083] S103: Determine, according to the container security level, a target container corresponding to the container running request on the container running node.
[0084] In this embodiment, the container security level can be divided into a normal level and a high security level. When the container security level is the normal level, the target container can be a normal container; when the container security level is the high security level, the target container can be a high security container.
[0085] S104: On the container running node, the network file system is mounted to the target container according to the mounting policy corresponding to the target container.
[0086] In this embodiment, when the target container is a common container, the network file system and the target container can be mounted according to the preset common container mounting policy; when the target container is a high-security container, the network file system and the target container can be mounted according to the preset high-security container mounting policy. Containers with different security levels can adopt different mounting strategies.
[0087] In a possible implementation, the container operation request may further include the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory; when the container security level is the normal level, the target container is a normal container, and accordingly, the above step S104 completes the mounting of the network file system and the target container at the container operation node according to the mounting policy corresponding to the target container, which may include:
[0088] S11: According to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, the network file system is mounted on the container running node.
[0089] S12: Initialize a first operating environment of a common container on the container operating node, and create a mount target directory in the first operating environment, where the first operating environment is a container host environment.
[0090] S13: On the container running node, establish a mapping relationship between the shared directory and the mount target directory.
[0091] S14: On the container running node, call the container engine to start the common container and complete the mounting of the network file system and the common container.
[0092] The shared directory is a directory of the file specified by the user in the network file system, and the mount target directory is a directory of the file specified by the user in the first operating environment.
[0093] In this embodiment, when generating a request to run a container, the container security level, the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory can be input by the user according to the page prompt, or the user can check the options provided on the page. The method of generating the request to run a container can be flexibly set by those skilled in the art, and no limitation is made here.
[0094] In this implementation, when the network file system to be mounted is determined, the sharing protocol corresponding to the network file system can be determined accordingly, but the specific type of the sharing protocol is not limited.
[0095] In this embodiment, the mount target directory is the directory of the user-specified file in the first operating environment (container host), and the shared directory is the directory of the user-specified file in the network file system. After establishing a mapping relationship between the shared directory and the mount target directory and completing the container mounting, the user can find the user-specified file according to the following link: start the container → mount target directory → mapping relationship → shared directory.
[0096] In this embodiment, the security requirements of common containers are not high. In order to improve the mounting efficiency, the mounting of common containers and network file systems can be performed directly in the container host. During the mounting process, the mounting target directory can be first established in the first operating environment (container host), and then the mapping relationship between the shared directory and the mounting target directory can be established on the container running node, and the container engine can be called to simply and conveniently complete the mounting of the network file system and the common container.
[0097] In a possible implementation, the above step S11 completes the mounting of the network file system and the container running node according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, and may include:
[0098] S111: Determine whether a network file system under a sharing protocol has been mounted under a first system directory of a container running node according to an address of the network file system to be mounted and a sharing protocol corresponding to the network file system.
[0099] S112: If not, then according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, the network file system is mounted to the first system directory, and the process goes to step S1033.
[0100] S113: If yes, determine whether there is a shared directory under the mount point of the first system directory.
[0101] S114: If it does not exist, create a shared directory under the mount point of the first system directory.
[0102] In this embodiment, the file specified by the user refers to the file that the user wants to obtain by mounting the container and the network file system. The first system directory refers to the system directory of the container running node (container host).
[0103] In this embodiment, if a network file system under a sharing protocol has been mounted under the first system directory of the container running node, and a shared directory exists under the mount point of the first system directory, it means that the container running node has previously mounted the network file system and the shared directory and does not need to do it again.
[0104] In this embodiment, when mounting the network file system and the container running node, it is first necessary to mount the network file system to the first system directory of the container running node, and then create a shared directory under the mount point of the first system directory. Since the container running node may have mounted the network file system multiple times before, in order to improve the efficiency of mounting and avoid repeated mounting, before mounting the network file system to the first system directory, it is possible to first determine whether the network file system under the sharing protocol has been mounted under the first system directory of the container running node, and determine whether there is a shared directory under the mount point of the first system directory.
[0105] In a possible implementation, the container operation request may further include the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory; when the container security level is a high security level, the target container is a high security container, and accordingly, the above step S104 completes the mounting of the network file system and the target container at the container operation node according to the mount policy corresponding to the target container, which may include:
[0106] S21: Initialize a second operating environment of the high-security container on the container operating node, and establish a mount target directory in the second operating environment, where the second operating environment is the internal environment of the container.
[0107] S22: On the container running node, generate a corresponding virtual network card according to the network card connected to the storage network, and add the virtual network card to the second running environment.
[0108] S23: Write the virtual network card, the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory into a target file of the second operating environment, where the target file corresponds to the container operation request.
[0109] S24: Call the container engine to start the high-security container, so that when the container engine reads the target file in the second operating environment, it uses the virtual network card to connect to the network, and mounts the network file system to the second system directory of the second operating environment according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system in the second operating environment; establishes a shared directory under the mount point of the second system directory, and establishes a mapping relationship between the shared directory and the mount target directory, so as to complete the mounting of the network file system and the high-security container.
[0110] The shared directory is a directory of the file specified by the user in the network file system, and the mount target directory is a directory of the file specified by the user in the first operating environment.
[0111] In this embodiment, the mount target directory is the directory of the file specified by the user in the second operating environment (inside the container). In order to ensure the security of the mount, the mounting of the high-security container is performed inside the container.
[0112] In this embodiment, if the container engine reads the target file in the second operating environment, it means that the container needs to be mounted and the next mounting step can be performed. If the target file in the second operating environment is not read, it means that the container does not need to be mounted and can be directly ignored.
[0113] In this embodiment, the high-security container may require a network when mounted and applied. In order to ensure security, a virtual network card can be generated based on the network card on the container running node, and the virtual network card can be used to connect to the network. Furthermore, in order to avoid tampering or influence by other programs, when the high-security container is mounted, the target file can be first generated in the second operating environment. When the container engine reads the target file in the second operating environment, it can mount the network file system and the high-security container inside the container according to the configuration in the target file, thereby improving the security of the platform. In addition, when mounting inside the container, there is no need to encrypt the file, which saves additional encryption steps, and also avoids the impact of the import of encrypted file data on the data reading and writing efficiency in the container, thereby improving the platform performance.
[0114] In this embodiment, after receiving the request to run the container, the corresponding target container can be allocated according to the container security level in the request to run the container, and the mounting of the network file system and the target container can be completed according to the mounting policy corresponding to the target container, that is, the container is allocated first, and then the mounting is completed. Through such a setting, when the network file system and the container are mounted, different containers and mounting policies can be allocated according to different security levels. When the security requirements of the container application scenario are high, a high-security container with a higher security level can be allocated, and the mounting policy corresponding to the high-security container can be used for mounting. There is no need to encrypt the specified file on the running node, which avoids tampering or influence by other programs, and improves the security of the platform. Furthermore, when mounting with the mounting policy corresponding to the high-security container, there is no need to encrypt the file, which saves additional encryption steps, and also avoids the impact of the import of encrypted file data on the data reading and writing efficiency in the container, thereby improving the platform performance.
[0115] Embodiment 2
[0116] Figure 2 This is a flow chart of a method for unloading a network file system from a container according to an embodiment of the present application. This embodiment uses a container platform as an execution subject to illustrate the method for unloading a network file system from a container. Figure 2 As shown, the method for unloading a network file system by a container may include the following steps:
[0117] S201: receiving a container termination request sent by a user terminal, where the container termination request includes target container information, a container security level, and an address of a network file system to be unloaded.
[0118] In this embodiment, the container platform may be a cloud server including multiple server hosts.
[0119] In this embodiment, when the user does not need to call the file in the network file system, a container end request can be sent to the container platform to end the mounting of the network file system and the target container.
[0120] In this embodiment, when generating an end container request, information such as the container security level, the address of the network file system to be unmounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory all correspond to the information in the run container request during mounting, and can be obtained from the corresponding run container request.
[0121] S202: Determine the target container to be unloaded according to the target container information.
[0122] In this embodiment, the target container information may be identification information of the container to be unloaded, such as a container number, etc. The target container information may be flexibly set by those skilled in the art, and no limitation is imposed herein.
[0123] S203: If the container security level of the target container is a normal level, a normal container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system.
[0124] In this embodiment, if the container security level of the target container is a normal level, the target container is a normal container, and the normal container uninstallation strategy can be used to complete the uninstallation of the target container and the network file system.
[0125] In a possible implementation, the end container request may further include a shared directory and a mount target directory. The above step S203 adopts a common container uninstallation strategy to complete the uninstallation of the container to be uninstalled and the network file system, which may include:
[0126] S31: Determine the container running node where the target container is located, and call the container engine on the container running node to stop the target container.
[0127] S32: deleting the mount target directory in the first running environment of the target container and the mapping relationship between the shared directory and the mount target directory on the container running node.
[0128] S33: Unmount the shared directory at the mount point of the first system directory of the container running node.
[0129] The first operating environment is the container host environment, the shared directory is the directory of the file specified by the user in the network file system, and the mount target directory is the directory of the file specified by the user in the first operating environment.
[0130] In this implementation, the container running node may be a host where the container is running, and one container running node may accommodate the running of multiple containers.
[0131] In this embodiment, after calling the container engine to stop the target container, corresponding to the mounting process of a common container, the mounting target directory in the first running environment of the target container and the mapping relationship between the shared directory and the mounting target directory are deleted in sequence on the container host, and the shared directory on the mount point is unmounted, so that the unmounting of the container to be unmounted and the network file system can be completed simply and conveniently.
[0132] S204: If the container security level of the target container is a high security level, a high security container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system.
[0133] In this embodiment, if the container security level of the target container is a high security level, the target container is a high security container, and a high security container uninstallation strategy can be used to complete the uninstallation of the target container and the network file system.
[0134] In a possible implementation, the end container request may further include a shared directory and a mount target directory. The above step S204 adopts a high-security container uninstallation strategy to complete the uninstallation of the container to be uninstalled and the network file system, which may include:
[0135] S41: Determine the container running node where the target container is located and the second running environment corresponding to the target container.
[0136] S42: Calling the container engine on the container running node to stop the target container, so that when the container engine reads the target file in the second running environment, it deletes the mapping relationship between the shared directory and the mounted target directory, and unmounts the shared directory under the mount point of the second system directory of the second running environment.
[0137] S43: Deleting the mount target directory in the second running environment of the target container and the virtual network card corresponding to the target container on the container running node.
[0138] Among them, the second operating environment is the internal environment of the container, the shared directory is the directory of the file specified by the user in the network file system, the mount target directory is the directory of the file specified by the user in the second operating environment, the virtual network card is generated according to the network card connected to the storage network when the target container is mounted, and the target file is generated according to the virtual network card when the target container is mounted, the address of the network file system, the sharing protocol corresponding to the network file system, the shared directory and the mount target directory.
[0139] In this embodiment, corresponding to the mounting process, in order to ensure the security of unloading, the unloading of the high-security container is also performed inside the container.
[0140] In this embodiment, if the container engine reads the target file in the second operating environment, it means that the container needs to be uninstalled and the next uninstallation step can be performed. If the target file in the second operating environment is not read, it means that the container does not need to be uninstalled and can be directly ignored.
[0141] In this embodiment, after calling the container engine to stop the target container, corresponding to the mounting process of the high-security container, when the container engine reads the target file in the second operating environment, it first deletes the mapping relationship between the shared directory and the mount target directory inside the container, and unmounts the shared directory under the mount point of the second system directory, and then deletes the mount target directory and the virtual network card on the container host, so that the unmounting of the container to be unmounted and the network file system can be completed simply and conveniently.
[0142] In a possible implementation, the end container request may further include a sharing protocol corresponding to the network file system. After completing the unloading of the target container and the network file system, it may further include: determining whether there is a target common container with the network file system mounted on the container running node according to the address of the network file system to be unloaded and the sharing protocol corresponding to the network file system; if not, unloading the network file system under the first system directory of the container running node.
[0143] In this embodiment, the ordinary container completes the mounting operation on the container running node (container host). The container running node may correspond to multiple containers. There may be multiple ordinary containers mounting the same network file system at the same time. In this case, the container running node only needs to mount the network file system once on the first system directory. After an ordinary container completes the unloading of the network file system, it is necessary to determine whether there are other ordinary containers mounting the network file system on the container running node. If not, the first system directory of the container running node can unmount the network file system. If so, the mounting with the network file system is retained. Through such a setting, mounting resources can be saved while ensuring mounting efficiency.
[0144] In this embodiment, after receiving the end container request sent by the user terminal, corresponding to the mounting process of the target container, the corresponding mounting strategy can be determined according to the security level of the target container. When the container security level of the target container is a high security level, the high security container uninstallation strategy can be adopted to complete the uninstallation of the target container and the network file system, and operate inside the container to avoid tampering or influence of other programs during the uninstallation process, thereby improving the security of the platform. When the container security level of the target container is a normal level, the normal container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system, and the target container can be uninstalled simply and conveniently by operating on the container host.
[0145] The following is an explanation of the method for mounting / unmounting a network file system on a container of the present application using a specific embodiment.
[0146] Embodiment 3
[0147] In a specific embodiment, a user wants to use a container to call a specified file A1 in a network file system A. The specific process of mounting / unmounting the network file system by a container is as follows:
[0148] In the first step, the user enters the container security level, the address of the network file system A to be mounted, the sharing protocol corresponding to the network file system A, the shared directory of the specified file A1 in the network file system A, and the mount target directory of the specified file A1 in the container running environment on the user terminal page. After receiving it, the user terminal generates a container running request based on the above information and sends it to the container platform.
[0149] In the second step, the container platform receives the container running request sent by the user terminal, and determines the container running node corresponding to the container running request. The container running node includes a network card connected to the storage network.
[0150] In the third step, the container platform determines that the container security level is a high security level, and determines that the target container corresponding to the container running request on the container running node is a high security container.
[0151] In the fourth step, the container platform initializes the second operating environment of the high-security container on the container running node, and establishes a mount target directory in the second operating environment. The second operating environment is the internal environment of the container.
[0152] In the fifth step, the container platform generates a corresponding virtual network card on the container running node based on the network card connected to the storage network, and adds the virtual network card to the second operating environment. It writes the virtual network card, the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory into the target file of the second operating environment, and calls the container engine to start the high-security container.
[0153] In the sixth step, when the container engine reads the target file in the second operating environment, it uses the virtual network card to connect to the network, and mounts the network file system to the second system directory of the second operating environment according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system in the second operating environment; creates a shared directory under the mount point of the second system directory, and establishes a mapping relationship between the shared directory and the mount target directory, completing the mounting of the network file system and the high-security container. The user can use the high-security container to call the specified file A1 in the network file system A.
[0154] In the seventh step, after the user calls the specified file A1 in the network file system A, the user selects the end container running option on the user terminal page. After the user terminal receives it, it generates an end container request based on the container security level in the associated running container request, the address of the network file system A to be mounted, the sharing protocol corresponding to the network file system A, the shared directory of the specified file A1 in the network file system A, and the mount target directory of the specified file A1 in the container running environment, as well as the target container information corresponding to the end container running option, and sends it to the container platform.
[0155] In the eighth step, the container platform receives the container end request sent by the user terminal, and determines the target container to be unloaded according to the target container information, and the container security level of the target container to be unloaded is a high security level.
[0156] In the ninth step, the container platform determines the container running node where the target container is located and the second running environment corresponding to the target container, calls the container engine on the container running node to stop the target container, and deletes the mount target directory in the second running environment of the target container and the virtual network card corresponding to the target container on the container running node.
[0157] In the tenth step, when the container engine reads the target file in the second operating environment, it deletes the mapping relationship between the shared directory and the mounted target directory, and unmounts the shared directory under the mount point of the second system directory of the second operating environment, completing the unmounting of the network file system and the high-security container.
[0158] Figure 3 This is a schematic diagram of the structure of a container platform according to an embodiment of the present application. Figure 3 As shown, the container platform includes: a first receiving module 31, which is used to receive a container operation request sent by a user terminal, and the container operation request includes a container security level; a first processing module 32, which is used to determine the container operation node corresponding to the container operation request, and the container operation node includes a network card connected to the storage network; according to the container security level, determine the target container corresponding to the container operation request at the container operation node; at the container operation node, according to the mount policy corresponding to the target container, complete the mounting of the network file system and the target container. In one embodiment, the description of the specific implementation function of the container platform can refer to steps S101-S104 in Example 1, which will not be repeated here.
[0159] Figure 4 This is a schematic diagram of the structure of a container platform according to another embodiment of the present application. Figure 4 As shown, the container platform includes: a second receiving module 41, which is used to receive a container end request sent by a user terminal, and the container end request includes target container information, container security level, and the address of the network file system to be uninstalled; a second processing module 42, which is used to determine the target container to be uninstalled and the corresponding network file system according to the target container information; if the container security level of the target container is a normal level, the normal container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system; if the container security level of the target container is a high security level, the high security container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system. In one embodiment, the description of the specific implementation function of the container platform can refer to steps S201-S204 in Example 1, which will not be repeated here.
[0160] Figure 5This is a schematic diagram of the structure of a container platform according to another embodiment of the present application. Figure 5 As shown, the container platform includes: a processor 101, and a memory 102 that is communicatively connected to the processor 101; the memory 102 stores computer execution instructions; the processor 101 executes the computer execution instructions stored in the memory 102 to implement the steps of the method of mounting / unmounting a network file system by a container in the above-mentioned method embodiments.
[0161] The container platform may be independent or part of a cloud platform (cloud server), and the processor 101 and the memory 102 may adopt existing hardware of the cloud platform.
[0162] In the above container platform, the memory 102 and the processor 101 are electrically connected directly or indirectly to realize data transmission or interaction. For example, these elements can be electrically connected to each other through one or more communication buses or signal lines, such as through a bus connection. The memory 102 stores computer-executable instructions for implementing the data access control method, including at least one software function module that can be stored in the memory 102 in the form of software or firmware. The processor 101 executes various functional applications and data processing by running the software programs and modules stored in the memory 102.
[0163] The memory 102 may be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electric erasable programmable read-only memory (EEPROM), etc. The memory 102 is used to store programs, and the processor 101 executes the programs after receiving the execution instruction. Furthermore, the software programs and modules in the above-mentioned memory 102 may also include an operating system, which may include various software components and / or drivers for managing system tasks (such as memory management, storage device control, power management, etc.), and may communicate with various hardware or software components to provide an operating environment for other software components.
[0164] The processor 101 may be an integrated circuit chip having the ability to process signals. The processor 101 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. The methods, steps, and logic diagrams disclosed in the embodiments of the present application may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
[0165] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the steps of each method embodiment of the present application.
[0166] An embodiment of the present application further provides a computer program product, including a computer program, which implements the steps of each method embodiment of the present application when executed by a processor.
[0167] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.
[0168] It should be further noted that, although the various steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0169] It should be understood that the above-mentioned device embodiments are only illustrative, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0170] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present application may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.
[0171] In the above embodiments, the description of each embodiment has its own emphasis. For the part not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0172] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the appended claims.
[0173] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for mounting a network file system in a container, characterized in that: include: Receiving a container operation request sent by a user terminal, wherein the container operation request includes a container security level; Determine a container running node corresponding to the container running request, wherein the container running node includes a network card connected to a storage network; Determine, according to the container security level, a target container corresponding to the container running node of the container running request; On the container running node, the network file system and the target container are mounted according to the mounting policy corresponding to the target container.
2. The method according to claim 1, characterized in that The container operation request also includes the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory and the mounting target directory; when the container security level is the normal level, the target container is a normal container, and accordingly, the node running the container completes the mounting of the network file system and the target container according to the mounting policy corresponding to the target container, specifically including: According to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, the mounting of the network file system and the container running node is completed; Initialize a first operating environment of the common container on the container operating node, and establish the mount target directory in the first operating environment, where the first operating environment is a container host environment; On the container running node, establishing a mapping relationship between the shared directory and the mount target directory; On the container running node, calling the container engine to start the common container, and completing the mounting of the network file system and the common container; The shared directory is a directory of files specified by the user in the network file system, and the mount target directory is a directory of files specified by the user in the first operating environment.
3. The method according to claim 2, characterized in that The step of completing the mounting of the network file system and the container running node according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system specifically includes: Determine, according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system, whether the network file system under the sharing protocol has been mounted under the first system directory of the container running node; If not, mounting the network file system to the first system directory according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system; If so, determine whether the shared directory exists under the mount point of the first system directory. If not, create the shared directory under the mount point of the first system directory.
4. The method according to any one of claims 1 to 3, characterized in that The request to run the container also includes a mount target directory. When the security level of the container is a high security level, the target container is a high security container. Accordingly, the node running the container completes the mounting of the network file system and the target container according to the mount policy corresponding to the target container, specifically including: Initialize the second operating environment of the high-security container on the container operating node, and establish the mount target directory in the second operating environment, where the second operating environment is the internal environment of the container; On the container running node, generating a corresponding virtual network card according to the network card connected to the storage network, and adding the virtual network card to the second running environment; Writing the virtual network card, the address of the network file system to be mounted, the sharing protocol corresponding to the network file system, the shared directory, and the mount target directory into a target file of the second operating environment, where the target file corresponds to the container operation request; Calling a container engine to start the high-security container, so that when the container engine reads the target file in the second operating environment, it uses the virtual network card to connect to the network, and mounts the network file system to the second system directory of the second operating environment according to the address of the network file system to be mounted and the sharing protocol corresponding to the network file system in the second operating environment; establishing the shared directory under the mount point of the second system directory, and establishing a mapping relationship between the shared directory and the mount target directory, so as to complete the mounting of the network file system and the high-security container; The shared directory is a directory of files specified by the user in the network file system, and the mount target directory is a directory of files specified by the user in the second operating environment.
5. A method for unloading a network file system from a container, characterized in that: include: receiving a container termination request sent by a user terminal, wherein the container termination request includes target container information, a container security level, and an address of a network file system to be unloaded; Determine the target container to be unloaded according to the target container information; If the container security level of the target container is a normal level, a normal container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system; If the container security level of the target container is a high security level, a high security container uninstallation strategy is adopted to complete the uninstallation of the target container and the network file system.
6. The method according to claim 5, characterized in that The end container request also includes a shared directory and a mount target directory, and the common container uninstallation strategy is adopted to complete the uninstallation of the container to be uninstalled and the network file system, specifically including: Determine the container running node where the target container is located, and call the container engine on the container running node to stop the target container; Deleting the mount target directory in the first running environment of the target container and the mapping relationship between the shared directory and the mount target directory on the container running node; Unmounting the shared directory at the mount point of the first system directory of the container running node; Among them, the first operating environment is a container host environment, the shared directory is a directory of the file specified by the user in the network file system, and the mount target directory is a directory of the file specified by the user in the first operating environment.
7. The method according to claim 5, characterized in that The end container request also includes a shared directory and a mount target directory, and the high-security container uninstallation strategy is adopted to complete the uninstallation of the container to be uninstalled and the network file system, specifically including: Determine a container running node where the target container is located and a second running environment corresponding to the target container; Calling a container engine on the container running node to stop the target container, so that when the container engine reads the target file in the second running environment, it deletes the mapping relationship between the shared directory and the mount target directory, and unmounts the shared directory under the mount point of the second system directory of the second running environment; Deleting the mount target directory in the second operating environment of the target container and the virtual network card corresponding to the target container on the container operating node; Among them, the second operating environment is the internal environment of the container, the shared directory is the directory of the file specified by the user in the network file system, the mount target directory is the directory of the file specified by the user in the second operating environment, the virtual network card is generated according to the network card connected to the storage network when the target container is mounted, and the target file is generated according to the virtual network card when the target container is mounted, the address of the network file system, the sharing protocol corresponding to the network file system, the shared directory and the mount target directory.
8. The method according to any one of claims 5 to 7, characterized in that: The container termination request further includes a sharing protocol corresponding to the network file system, and after the target container and the network file system are uninstalled, the following further includes: Determine whether there is a target common container for mounting the network file system on the container running node according to the address of the network file system to be unloaded and the sharing protocol corresponding to the network file system; If not, the network file system is uninstalled under the first system directory of the container running node.
9. A container platform, characterized in that: comprising a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 4 or 5 to 8.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 4 or 5 to 8 when executed by a processor.
Citation Information
Cited By
Data processing method and system
CN121501363A