Container kernel parameter adjusting method and system

By using preset CNI plug-ins and configuration files in the container cluster management tool, the kernel parameter dictionary is generated and adjusted, the problem of turning on privileged mode in the existing technology is solved, and a secure and flexible container kernel parameter adjustment is achieved.

CN119987938APending Publication Date: 2025-05-13SINA TECH (CHINA) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411985941.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the prior art, when adjusting the Pod container kernel parameters in the container cluster management tool, it is necessary to enable the privileged mode, which leads to security problems. How to adjust and optimize the Pod container kernel parameters without turning on the privileged mode.

Method used

When creating a container group Pod through the preset CNI plug-in, the query results of multiple resource parameters related to the Pod are obtained, and compared with the preset configuration file to generate a kernel parameter dictionary, and the container kernel parameter adjustment is performed based on the dictionary.

Benefits of technology

It realizes that the kernel parameter adjustment of the container in the Pod without turning on the privileged mode, ensuring system security, and supports kernel parameter adjustment configuration based on global, Node name, Node tag, Namespace name, Namespace tag, Pod tag and Pod annotation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987938A_ABST
    Figure CN119987938A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a container kernel parameter adjustment method and system, and the method comprises the steps: obtaining a query result of a plurality of resource parameters related to a Pod through a preset CNI plug-in when a container group Pod is created, and the plurality of resource parameters comprise a Pod label, a Namespace name, a Namespace label, a node name and a node label; a preset configuration file is read, the query result is compared with the configuration file, and the configuration file comprises a preset value of at least one resource parameter and a corresponding kernel parameter adjusting mode; under the condition that the query result is matched with the preset value of the at least one resource parameter, generating a kernel parameter dictionary based on a corresponding kernel parameter adjustment mode; and performing container kernel parameter adjustment based on the kernel parameter dictionary. According to the technical scheme, on the basis of the CNI plug-in, when the Pod is started, kernel parameter adjustment can be carried out on the container in the Pod according to the unified configuration file, a privilege mode does not need to be started any more, and the safety of the whole system is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technology, and in particular to a container kernel parameter adjustment method and system. Background Art

[0002] Containers are a lightweight virtualization technology used to encapsulate applications and all their dependencies and configurations so that they can run in different computer environments. Containers use operating system-level virtualization technology to package applications and their dependencies in an independent unit, ensuring that applications run consistently in different environments. Accordingly, some container cluster management tools, such as kubernetes (K8s for short), have also been increasingly widely used, and can optimize service network performance by modifying Pod container kernel parameters.

[0003] In the prior art, when adjusting the kernel parameters of the container in the Pod (container group) in the container cluster management tool, it is necessary to enable the privileged mode, and enabling the privileged mode will cause security problems; therefore, how to achieve the adjustment and optimization of the kernel parameters of the Pod container without enabling the privileged mode is a problem that needs to be solved. Summary of the invention

[0004] The embodiments of the present invention provide a container kernel parameter adjustment method and system, which are used to adjust the kernel parameters of the container in the Pod without turning on the privileged mode, thereby ensuring system security.

[0005] To achieve the above-mentioned purpose, on the one hand, an embodiment of the present invention provides a container kernel parameter adjustment method, comprising: when creating a container group Pod, obtaining query results of multiple resource parameters related to the Pod through a preset CNI plug-in, the multiple resource parameters including: Pod label, Namespace name of the namespace Namespace corresponding to the Pod, Namespace label, node name of the node Node where the Pod is located, and node label; reading a preset configuration file, and comparing the query result with the configuration file, the configuration file including a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter; when the query result matches the preset value of at least one resource parameter, generating a kernel parameter dictionary based on the corresponding kernel parameter adjustment method; indicating the kernel parameters that need to be adjusted in the kernel parameter dictionary; and adjusting the container kernel parameters based on the kernel parameter dictionary.

[0006] On the other hand, an embodiment of the present invention provides a container kernel parameter adjustment system, including: a query module, which is used to obtain query results of multiple resource parameters related to the Pod through a preset CNI plug-in when creating a container group Pod, and the multiple resource parameters include: Pod label, Namespace name of the namespace Namespace corresponding to the Pod, Namespace label, node name of the node Node where the Pod is located, and node label; a matching module, which is used to read a preset configuration file and compare the query result with the configuration file, and the configuration file includes a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter; when the query result matches the preset value of at least one resource parameter, a kernel parameter dictionary is generated based on the corresponding kernel parameter adjustment method; the kernel parameter adjustment module indicating the kernel parameter adjustment that needs to be adjusted in the kernel parameter dictionary is used to adjust the container kernel parameters based on the kernel parameter dictionary.

[0007] At the same time, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the aforementioned container kernel parameter adjustment method is implemented.

[0008] In addition, an embodiment of the present invention also provides a computer device, which includes: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by one or more processors, the one or more processors implement the aforementioned container kernel parameter adjustment method.

[0009] The above technical solution has the following beneficial effects:

[0010] This technical solution is based on the CNI plug-in method. When the Pod is started, the kernel parameters of the container in the Pod can be adjusted according to a unified configuration file, without turning on the privileged mode as in the prior art, thereby ensuring the security of the entire system.

[0011] In addition, this technical solution also has the following characteristics:

[0012] In the prior art, not all kernel parameters can be configured in Pod privileged mode, but only for the configured Pod, and cannot be uniformly configured based on node name, node label, Namespace name, Namespace label, global, etc.; after adopting the technical solution of the present application, the adjustment of the kernel parameters of the container in the Pod is not restricted by the security level of container cluster management tools such as Kubernetes. By adjusting the configMap of the kernel parameter configuration file, the kernel parameters of the container in the Pod can be dynamically adjusted. It supports kernel parameter adjustment configuration based on global, Node name, Node label, Namespace name, Namespce label, Pod label and Pod annotation. Almost all operating system kernel parameters can be adjusted, which greatly facilitates user use. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0014] Figure 1 It is a flow chart of a method for adjusting container kernel parameters according to an embodiment of the present invention;

[0015] Figure 2 This is a diagram of a container kernel parameter adjustment system according to an embodiment of the present invention;

[0016] Figure 3 is a system composition diagram of a specific embodiment of the present invention;

[0017] Figure 4 It is a schematic diagram of the contents of the configuration file in the present invention;

[0018] Figure 5 It is a schematic diagram of the contents of a configuration file in a specific embodiment of the present invention. DETAILED DESCRIPTION

[0019] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0020] like Figure 1 As shown, an embodiment of the present invention provides a container kernel parameter adjustment method, including:

[0021] S101. When creating a Pod (container group), obtain query results of multiple resource parameters related to the Pod through a preset CNI (container network interface) plug-in, where the multiple resource parameters include: Pod label, Namespace name of the Namespace corresponding to the Pod, Namespace label, node name of the Node where the Pod is located, and node label;

[0022] S102, reading a preset configuration file, and comparing the query result with the configuration file, the configuration file including a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter;

[0023] S103, when the query result matches the preset value of the at least one resource parameter, generating a kernel parameter dictionary based on the corresponding kernel parameter adjustment method; the kernel parameter dictionary indicates the kernel parameters that need to be adjusted;

[0024] S104: Adjust container kernel parameters based on the kernel parameter dictionary.

[0025] To solve the aforementioned problem, in this technical solution, a preset CNI plug-in is used to query and obtain items such as container ID, Pod name, Pod label, node name, node label, Namespace name, Namespace label, etc., and the query result is matched with a configuration file containing preset values ​​of items with the same name. If the query result is the same as the preset value of the item with the same name, the container kernel parameters are adjusted according to the kernel parameter adjustment requirements specified in the configuration file. In this way, there is no need to enable the privileged mode as in the prior art, and the prior art can only be configured for Pod. After adopting this method, unified configuration can also be performed based on node name, node label, Namespace name, Namespace label, global, etc.

[0026] Furthermore, the step S101 includes:

[0027] S1011. When presetting the CNI plug-in, obtain the node name of the node where the CNI plug-in is located through the system environment variable;

[0028] S1012, querying the node label of the node by calling an API interface and passing the node name;

[0029] S1013. Obtain the container ID of the container in the currently created Pod through the CNI plug-in;

[0030] S1014. Call the CRI interface through the container ID to obtain the Pod name of the Pod and the Namespace name of the Namespace corresponding to the Pod;

[0031] S1015. Obtain the Pod label of the Pod by calling the API interface and passing the Pod name and the Namespace name;

[0032] S1016. Obtain the Namespace label of the Namespace corresponding to the Pod by calling the API interface and passing the Namespace name.

[0033] Furthermore, each kernel parameter adjustment method includes a kernel parameter file to be adjusted and a parameter value of the kernel parameter file to be adjusted; the style of the kernel parameter adjustment requirement is as follows: Figure 4 or Figure 5 As shown in , the part after "kernel" is the kernel parameter adjustment requirement, for example, "net.core.somaxconn":500, "net.core.somaxconn" is the kernel parameter file to be adjusted, and "500" after the colon is the parameter value of the kernel parameter file. When a kernel parameter adjustment requirement is written into the kernel parameter dictionary and executed, when the container in the Pod is started, the parameter value in the kernel parameter adjustment requirement will be written into the corresponding kernel parameter file.

[0034] The step S103 specifically includes:

[0035] S1031. For each resource parameter, compare the query result of the resource parameter with the preset value of the resource parameter. If the two are consistent, write the kernel parameter adjustment method corresponding to the resource parameter in the configuration file into the kernel parameter dictionary.

[0036] Furthermore, the configuration file also includes a global kernel parameter adjustment method;

[0037] Before step S104, the method further includes:

[0038] S1038. Write the global kernel parameter adjustment method into the kernel parameter dictionary.

[0039] Furthermore, the process of step S1013 also includes: obtaining a container network configuration path;

[0040] The step S104 specifically includes:

[0041] S1041, checking whether there is configuration overlap in the kernel parameter dictionary, where the configuration overlap refers to the existence of at least two kernel parameter adjustment methods with the same kernel parameter file to be adjusted;

[0042] S1042: if there is configuration overlap in the kernel parameter dictionary, retain the kernel parameter adjustment method with a higher priority according to the priorities of the at least two kernel parameter adjustment methods;

[0043] S1043. When there is no configuration overlap in the kernel parameter dictionary, find each kernel parameter file to be adjusted in the kernel parameter dictionary according to the container network configuration path, and configure corresponding parameter values.

[0044] In this process, the specific process of retaining the high-priority kernel parameter adjustment requirements (that is, the low-level configuration is overwritten by the high-level configuration) is as follows: when the CNI plug-in queries the node where the current Pod is located and finds that there is a label such as "app": "web", it is matched with Figure 4 The configuration file shown is compared with the one shown in the figure. Since the labels are the same as those under node in the configuration file, the corresponding kernel parameter adjustment requirements (i.e. the contents of the kernel section "net.core.somaxconn":500 and net.ipv4.tcp_syncookies") are written into the kernel parameter dictionary. At the same time, the global kernel parameter adjustment requirements (net.core.somaxconn":200 and net.ipv4.tcp_tw_reuse":1) are also written into the kernel parameter dictionary.

[0045] Afterwards, due to configuration overlap (the kernel parameter adjustment requirements of "global" and "node" both involve the kernel parameter file "net.core.somaxconn" to be adjusted), the configuration needs to be overwritten, and because the global priority is lower than the node, the global "net.core.somaxconn":200 is replaced by the node "net.core.somaxconn":500. In addition, "global" "net.ipv4.tcp_tw_reuse":1 must take effect globally, and "net.ipv4.tcp_syncookies":0 on "node" is for this node, and there is no higher-level configuration override, so it will eventually take effect. At this point, the kernel parameter dictionary that needs to be modified when this Pod is started is:

[0046] {"net.core.somaxconn":500,"net.ipv4.tcp_syncookies":0,"net.ipv4.tcp_tw_reuse":1}.

[0047] Furthermore, the priorities of the kernel parameter adjustment requirements are, from high to low, as follows:

[0048] Pod annotation level, indicating that the Pod adjusts the container kernel parameters. The kernel parameters that need to be adjusted are obtained from the Pod annotation;

[0049] Pod label level, indicating that when the Pod label in the query result includes the preset value of the Pod label in the configuration file, the Pod adjusts the container kernel parameters;

[0050] Namespace name level, indicating that when the Namespace name corresponding to the Pod in the query result is equal to the preset value of the Namespace name in the configuration file, the Pod adjusts the container kernel parameters;

[0051] Namespace label level, indicating that when the Namespace label corresponding to the Pod in the query result includes the preset value of the Namespace label in the configuration file, the Pod adjusts the container kernel parameters;

[0052] Node name level, indicating that when the node name in the query result is equal to the preset value of the node name in the configuration file, the Pod on the node adjusts the container kernel parameters;

[0053] The node label level indicates that when the node label in the query result includes the preset value of the node label in the configuration file, the Pod on the node adjusts the container kernel parameters;

[0054] The global level means that all Pods adjust the container kernel parameters.

[0055] Furthermore, the process of step S1015 also includes: obtaining the Pod annotation of the Pod;

[0056] Before step S104, the method further includes:

[0057] S1039. Write the kernel parameter adjustment method in the Pod annotation into the kernel parameter dictionary.

[0058] like Figure 2 As shown, an embodiment of the present invention further provides a container kernel parameter adjustment system, including:

[0059] The query module 21 is used to obtain query results of multiple resource parameters related to the Pod through a preset CNI plug-in when creating a container group Pod. The multiple resource parameters include: Pod label, Namespace name of the namespace Namespace corresponding to the Pod, Namespace label, node name of the node Node where the Pod is located, and node label;

[0060] The matching module 22 is used to read a preset configuration file and compare the query result with the configuration file, wherein the configuration file includes a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter; if the query result matches the preset value of the at least one resource parameter, a kernel parameter dictionary is generated based on the corresponding kernel parameter adjustment method; the kernel parameter dictionary indicates the kernel parameter that needs to be adjusted;

[0061] The adjustment module 23 is used to adjust the container kernel parameters based on the kernel parameter dictionary.

[0062] Furthermore, the query module 21 includes:

[0063] A node name query submodule, used to obtain the node name of the node where the CNI plug-in is located through the system environment variable when the CNI plug-in is pre-installed;

[0064] A node label query submodule is used to query the node label of the node by calling an API interface and passing the node name;

[0065] A container ID query submodule, used to obtain the container ID of the container in the currently created Pod through the CNI plug-in;

[0066] A Namespace name query submodule is used to call the CRI interface through the container ID to obtain the Pod name of the Pod and the Namespace name of the Namespace corresponding to the Pod;

[0067] A Pod label query submodule, used to obtain the Pod label of the Pod by calling the API interface and passing the Pod name and the Namespace name;

[0068] The Namespace label query submodule is used to obtain the Namespace label of the Namespace corresponding to the Pod by calling the API interface and passing the Namespace name.

[0069] Furthermore, each kernel parameter adjustment method includes a kernel parameter file to be adjusted and a parameter value of the kernel parameter file to be adjusted;

[0070] The matching module 22 also includes a kernel parameter writing submodule, which is specifically used to: for each resource parameter, compare the query result belonging to the resource parameter with the preset value of the resource parameter, and when the two are consistent, write the kernel parameter adjustment method corresponding to the resource parameter in the configuration file into the kernel parameter dictionary.

[0071] Furthermore, the configuration file also includes a global kernel parameter adjustment method;

[0072] The container kernel parameter adjustment system further includes: a global parameter writing module, which is used to write the global kernel parameter adjustment mode into the kernel parameter dictionary before adjusting the container kernel parameter based on the kernel parameter dictionary.

[0073] Furthermore, the container ID query submodule is also used to: obtain the container network configuration path;

[0074] The adjustment module 23 is specifically used to: check whether there is configuration overlap in the kernel parameter dictionary, and the configuration overlap refers to the existence of at least two kernel parameter adjustment methods with the same kernel parameter file to be adjusted; if there is configuration overlap in the kernel parameter dictionary, retain the kernel parameter adjustment method with a high priority according to the priorities of the at least two kernel parameter adjustment methods; if there is no configuration overlap in the kernel parameter dictionary, find each kernel parameter file to be adjusted in the kernel parameter dictionary according to the container network configuration path, and configure the corresponding parameter value.

[0075] Furthermore, the priorities of the kernel parameter adjustment methods are, from high to low, as follows:

[0076] Pod annotation level, indicating that the Pod adjusts the container kernel parameters. The kernel parameters that need to be adjusted are obtained from the Pod annotation;

[0077] Pod label level, indicating that when the Pod label in the query result includes the preset value of the Pod label in the configuration file, the Pod adjusts the container kernel parameters;

[0078] Namespace name level, indicating that when the Namespace name corresponding to the Pod in the query result is equal to the preset value of the Namespace name in the configuration file, the Pod adjusts the container kernel parameters;

[0079] Namespace label level, indicating that when the Namespace label corresponding to the Pod in the query result includes the preset value of the Namespace label in the configuration file, the Pod adjusts the container kernel parameters;

[0080] Node name level, indicating that when the node name in the query result is equal to the preset value of the node name in the configuration file, the Pod on the node adjusts the container kernel parameters;

[0081] The node label level indicates that when the node label in the query result includes the preset value of the node label in the configuration file, the Pod on the node adjusts the container kernel parameters;

[0082] The global level means that all Pods adjust the container kernel parameters.

[0083] Furthermore, the Namespace name query submodule is also used to: obtain Pod annotations;

[0084] The container kernel parameter adjustment system also includes a Pod annotation writing module, which is used to write the kernel parameter adjustment method in the Pod annotation into the kernel parameter dictionary before adjusting the container kernel parameters based on the kernel parameter dictionary.

[0085] The following is through Figure 3 A specific embodiment shown is used to explain the above technical solution in detail:

[0086] In this specific embodiment, the Kubernetes API (i.e. Figure 3 001) is used to manage and operate Kubernetes clusters;

[0087] Node Figure 3 002) in the figure is a node in the cluster;

[0088] Business Pod (i.e. Figure 3 003) in the figure is the business Pod deployed through Deployment, StatefulSet, or DaemonSet;

[0089] Business container (ie Figure 3 004) in the figure is a container in which a business program is deployed;

[0090] The optimized Pod is 005 in the figure. This Pod will be on each Node ( Figure 3 001) in the above, and the new Node added to the cluster will also be automatically deployed (using Kubernetes DaemonSet mode for deployment);

[0091] pkt (PodKernel Tuning) program (ie Figure 3 006 in the figure is an application developed independently using Golang, which implements the CNI (Container Network Interface) plug-in function and is used to implement the container ( Figure 3 004) Logical processing of kernel parameter tuning;

[0092] / opt / cni / bin / (ie Figure 3 007) is to tune the Pod to mount Node during startup ( Figure 3 002) on the directory / opt / cni / bin / , which is used to tune the pkt program in the Pod and can be found on Node( Figure 3 002) is chained by CNI;

[0093] unix: / / / run / containerd / containerd.sock( Figure 3 The function of 008) is that when the pkt program is called by CNI, it communicates with the CRI (Container Runtime Interface) of Kubernetes through this Unix Sock to obtain the container information of the business container;

[0094] Netns (container network configuration path) Figure 3 009) is the container network file created by the business container through CNI. The pkt program will modify this file.

[0095] Configuration File( Figure 3 010) is a configuration file stored using the configMap method in Kubernetes, which is used for Pod ( Figure 3 003) Unified configuration file for container kernel parameter tuning.

[0096] The specific implementation process (i.e., pkt program execution logic) is:

[0097] 1) Create a Pod in Kubernetes ( Figure 3 003), the CNI interface is called. The pkt program is a CNI plug-in that implements the CNI interface. This program is also called when a Pod is created.

[0098] 2) When calling pkt, CNI will pass several parameters. This pkt needs to obtain the corresponding container in the Pod ( Figure 3 004) and the container network configuration path (Netns);

[0099] 3) Call the CRI interface through the containerID (this sock exists on the node, the corresponding path is: unix: / / / run / containerd / containerd.sock) to obtain the Pod ( Figure 3 Namespace and Pod name of 003)

[0100] 4) Call the Kubernetes API interface, pass the Namespace name and Pod name corresponding to the Pod, and query the Pod label and Pod annotation;

[0101] 5) Call the Kubernetes API interface, pass the Namespace name, and query the Namespace label;

[0102] 6) When the pkt program is deployed to the corresponding node, the node name (Node name) can be obtained through the system environment variables; by calling the Kubernetes API interface and passing the Node name, the node label can be queried;

[0103] 7) At this point, you can get the Node name, Node label, Namespce name, Namespce label, Pod name, Pod label, and Pod annotation;

[0104] 8) Call the Kubernetes API interface again to read the configuration file (the configuration file has been deployed in the Kubernetes cluster when the pkt service is deployed). The content of the configuration file can be found in Figure 5 As shown;

[0105] 9) Pass the Node name, Node label, Namespce name, Namespce label, and Pod label, and perform hierarchical processing on the configuration in the configuration file. If there is configuration overlap, the low-level configuration can be overwritten by the high-level configuration;

[0106] The principles of hierarchical processing are:

[0107] The global level is 0, and global represents Pod ( Figure 3 The container kernel parameters in 003) will be adjusted;

[0108] The node tag level is 1. If Node( Figure 3 If the node label is included in 002), the kernel parameters of the container of the Pod on this Node are adjusted;

[0109] The node name level is 2. If Node( Figure 3 If the node name in 002) is equal to the node name in the configuration file, adjust the kernel parameters of the container in the Pod on this Node;

[0110] The namespace label level is 3. If the Pod ( Figure 3 If the Namespace where 003) is located contains the same namespace label as the configuration file, the Pod adjusts the container kernel parameters;

[0111] The namespace name level is 4. If the name of the Namespace where the Pod is located is equal to the name of the namespace in the configuration file, the container kernel parameters of this Pod are adjusted;

[0112] The Pod label level is 5. If the Pod label contains the Pod label in the configuration file, the container kernel parameters of this Pod are adjusted;

[0113] In addition, when there is a Pod annotation, the container kernel parameters are adjusted according to the Pod annotation, and the adjusted kernel parameters are obtained from the Pod annotation;

[0114] 10) Finally, a dictionary containing only the kernel parameters that need to be adjusted is generated. If the dictionary is empty, it means that this Pod does not need container kernel tuning.

[0115] 11) Traverse the kernel parameter dictionary and modify the key value. For example, the key value of "net.ipv4.tcp_tw_reuse" needs to be modified to " / proc / sys / net / ipv4 / tcp_tw_reuse". In this way, the path of the file where the kernel parameter that needs to be modified is located is obtained;

[0116] 12) Finally, the parameter Netns (container network configuration path) will be passed to the method for modifying container network parameters (this method is provided by CNI and does not need to be implemented separately), and the value of the file " / proc / sys / net / ipv4 / tcp_tw_reuse" will be directly rewritten to the value corresponding to the key in the kernel parameter dictionary;

[0117] 13) When all pkts are executed, the container network configuration used when the container in the Pod is started is modified, and the corresponding kernel parameters are also adjusted accordingly.

[0118] The disclosed embodiments are described above to enable any person skilled in the art to implement or use the present invention. Various modifications of these embodiments are obvious to those skilled in the art, and the general principles defined herein may also be applied to other embodiments without departing from the spirit and scope of the present disclosure. Therefore, the present disclosure is not limited to the embodiments given herein, but is consistent with the broadest scope of the principles and novel features disclosed in this application.

[0119] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A container kernel parameter adjustment method, characterized in that: include: When creating a container group Pod, the query results of multiple resource parameters related to the Pod are obtained through the preset container network interface CNI plug-in. The multiple resource parameters include: Pod label, Namespace name of the namespace Namespace corresponding to the Pod, Namespace label, node name of the node Node where the Pod is located, and node label; Reading a preset configuration file and comparing the query result with the configuration file, the configuration file including a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter; In the case where the query result matches the preset value of the at least one resource parameter, a kernel parameter dictionary is generated based on the corresponding kernel parameter adjustment method; the kernel parameter dictionary indicates the kernel parameter that needs to be adjusted; Container kernel parameters are adjusted based on the kernel parameter dictionary.

2. The container kernel parameter adjustment method according to claim 1, characterized in that: When creating a container group Pod, the query results of multiple resource parameters related to the Pod are obtained through the preset CNI plug-in, including: When pre-installing the CNI plug-in, obtaining the node name of the node where the CNI plug-in is located through the system environment variable; Query the node label of the node by calling the API interface and passing the node name; Obtain the container ID of the container in the currently created Pod through the CNI plug-in; Call the CRI interface through the container ID to obtain the Pod name of the Pod and the Namespace name of the Namespace corresponding to the Pod; Obtain the Pod label of the Pod by calling the API interface and passing the Pod name and the Namespace name; By calling the API interface and passing the Namespace name, the Namespace label of the Namespace corresponding to the Pod is obtained.

3. The container kernel parameter adjustment method according to claim 2, characterized in that: Each kernel parameter adjustment method includes a kernel parameter file to be adjusted and a parameter value of the kernel parameter file to be adjusted; When the query result matches the preset value of the at least one resource parameter, generating a kernel parameter dictionary based on the corresponding kernel parameter adjustment method specifically includes: For each resource parameter, the query result belonging to the resource parameter is compared with the preset value of the resource parameter. When the two are consistent, the kernel parameter adjustment method corresponding to the resource parameter in the configuration file is written into the kernel parameter dictionary.

4. The container kernel parameter adjustment method according to claim 3, characterized in that: The configuration file also includes a global kernel parameter adjustment method; Before adjusting the container kernel parameters based on the kernel parameter dictionary, the method further includes: The global kernel parameter adjustment mode is written into the kernel parameter dictionary.

5. The container kernel parameter adjustment method according to claim 4, characterized in that: The method further comprises: In the process of obtaining the container ID of the container in the currently created Pod through the CNI plug-in, obtaining the container network configuration path; The adjusting of the container kernel parameters based on the kernel parameter dictionary specifically includes: Checking whether there is configuration overlap in the kernel parameter dictionary, wherein the configuration overlap refers to the existence of at least two kernel parameter adjustment methods with the same kernel parameter file to be adjusted; In the case where there is configuration overlap in the kernel parameter dictionary, retaining a kernel parameter adjustment method with a higher priority according to the priorities of the at least two kernel parameter adjustment methods; In the case where there is no configuration overlap in the kernel parameter dictionary, each kernel parameter file to be adjusted in the kernel parameter dictionary is found according to the container network configuration path, and the corresponding parameter value is configured.

6. The container kernel parameter adjustment method according to claim 5, characterized in that: The priorities of the kernel parameter adjustment methods are as follows, from high to low: Pod annotation level, indicating that the Pod adjusts the container kernel parameters. The kernel parameters that need to be adjusted are obtained from the Pod annotation; Pod label level, indicating that when the Pod label in the query result includes the preset value of the Pod label in the configuration file, the Pod adjusts the container kernel parameters; Namespace name level, indicating that when the Namespace name corresponding to the Pod in the query result is equal to the preset value of the Namespace name in the configuration file, the Pod adjusts the container kernel parameters; Namespace label level, indicating that when the Namespace label corresponding to the Pod in the query result includes the preset value of the Namespace label in the configuration file, the Pod adjusts the container kernel parameters; Node name level, indicating that when the node name in the query result is equal to the preset value of the node name in the configuration file, the Pod on the node adjusts the container kernel parameters; The node label level indicates that when the node label in the query result includes the preset value of the node label in the configuration file, the Pod on the node adjusts the container kernel parameters; The global level means that all Pods adjust the container kernel parameters.

7. The container kernel parameter adjustment method according to claim 6, characterized in that: The method further comprises: In the process of obtaining the Pod label of the Pod by calling the API interface and passing the Pod name and the Namespace name, obtaining the Pod annotation of the Pod; Before adjusting the container kernel parameters based on the kernel parameter dictionary, the method further includes: The kernel parameter adjustment method in the Pod annotation is written into the kernel parameter dictionary.

8. A container kernel parameter adjustment system, characterized in that: include: A query module is used to obtain query results of multiple resource parameters related to the Pod through a preset CNI plug-in when creating a container group Pod. The multiple resource parameters include: Pod label, Namespace name of the namespace Namespace corresponding to the Pod, Namespace label, node name of the node Node where the Pod is located, and node label; a matching module, configured to read a preset configuration file and compare the query result with the configuration file, wherein the configuration file includes a preset value of at least one resource parameter and a kernel parameter adjustment method corresponding to the resource parameter; if the query result matches the preset value of the at least one resource parameter, generating a kernel parameter dictionary based on the corresponding kernel parameter adjustment method; the kernel parameter dictionary indicates the kernel parameter that needs to be adjusted; An adjustment module is used to adjust container kernel parameters based on the kernel parameter dictionary.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the container kernel parameter adjustment method according to any one of claims 1 to 7 is implemented.

10. A computer device, characterized in that: It includes: one or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the container kernel parameter adjustment method as described in any one of claims 1 to 7.