Information processing method for container isolation and method for realizing high service availability
By safely strengthening and isolation during container image construction and operation, the security risks in container technology are solved, and effective isolation and security improvement of container resources are achieved.
Patent Information
- Application Number
- CN202510204979.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-13
AI Technical Summary
After the introduction of container technology, it brought about security risks to the container itself, such as container mirroring risks, container operation risks, container network risks, container interface risks and host environmental risks, resulting in poor container security.
Provides an information processing method for container isolation, including security hardening when building container images, verifying the mirror source, building the image based on preset mirror instructions, processing sensitive information in the container, and configuring independent partitions, user groups and audit rules when the container runs to achieve resource isolation and auditing.
Through this method, the risk of uncontrolled containers is eliminated, the risk of backdoors, sensitive information risks and unsafe software risks in mirror construction are avoided, the effective isolation of container computing, storage and network resources is ensured, and the security of containers is improved.
Smart Images

Figure CN119987953A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of cloud platforms, and in particular to an information processing method for container isolation and a method for achieving high service availability. Background Art
[0002] Containers are currently a common tool for software deployment and operation. They are generally run on servers. They are characterized by resource isolation between containers and between containers and host machines. Their main purpose is to ensure that containers do not interfere with each other and to ensure the security of container data. However, the introduction of container technology has brought about security risks of the container itself, including container image risks, container operation risks, container network risks, container interface risks, and host environment risks. Summary of the invention
[0003] The main purpose of the present disclosure is to provide an information processing method for container isolation and a method for achieving high service availability.
[0004] In order to achieve the above-mentioned purpose, according to the first aspect of the present disclosure, there is provided an information processing method for container isolation, including: performing security reinforcement on the container image when building the container image, including verifying the image source; building the image based on preset image instructions; processing the data belonging to preset sensitive information in the container; and reinforcing isolation when the container is running, including: configuring independent partitions for the container; configuring user groups for the container so that users in the user groups can control the permissions of the container daemon; configuring audit rules for the container daemon to audit the container daemon based on the audit rules; and auditing the files and directories related to the container.
[0005] Optionally, when verifying the image source, the trust mechanism of the container is configured to be enabled, wherein the image is digitally signed for data sent and received through the trust mechanism, and the digital signature is used to verify the image.
[0006] Optionally, when building an image based on a preset image instruction, instructions for local data can be preferentially called as the preset image instruction.
[0007] Optionally, processing the data belonging to preset sensitive information in the container includes: encrypting the preset sensitive information, and decrypting the data by a user who is authorized to use the encrypted data.
[0008] Optionally, after the container daemon process is audited based on the audit rules, logs generated by the audit process are stored in a pre-created audit partition.
[0009] Optionally, before auditing the files and directories related to the container, the method further includes obtaining a target audit rule configured by a user to audit the files and directories related to the container based on the target audit rule.
[0010] According to the second aspect of the present disclosure, a method for achieving high availability of services is provided, including: after the container is deployed with the service, registering container information to the etcd storage component through the REST service; periodically querying the latest container information of the etcd storage component through the Confd configuration component, generating a Haproxy configuration file based on the latest container information, and automatically refreshing the Haproxy service.
[0011] According to a third aspect of the present disclosure, a computer-readable storage medium is provided, storing computer instructions, wherein the computer instructions are used to enable the computer to execute the method according to any one of claims 1 to 8.
[0012] According to a fourth aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the method described in any one implementation of the first aspect.
[0013] This embodiment is used for an information processing method for container isolation and a method for achieving high availability of services, wherein the information processing method for container isolation includes, when building a container image, performing security reinforcement on the container image, including verifying the image source; building an image based on preset image instructions; processing data in the container that belongs to preset sensitive information; and reinforcing isolation when the container is running, including: configuring independent partitions for the container; configuring user groups for the container so that users in the user group can control the permissions of the container daemon; configuring audit rules for the container daemon to audit the container daemon based on the audit rules; auditing files and directories related to the container. By adopting this container image security reinforcement solution, the risk of uncontrolled containers can be eliminated from the source, and the backdoor risk, sensitive information risk, unsafe software risk, etc. in image construction can be effectively avoided. Ensure that container computing, storage, and network resources are effectively isolated. It overcomes the defect of poor container security in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the specific embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0015] Figure 1 is a schematic diagram of the composition of an information processing method for container isolation according to an embodiment of the present disclosure;
[0016] Figure 2 is an architectural diagram of a method for achieving high availability of services according to an embodiment of the present disclosure;
[0017] Figure 3 is a schematic diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0018] In order to enable those skilled in the art to better understand the scheme of the present disclosure, the technical scheme in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present disclosure.
[0019] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so as to describe the embodiments of the present disclosure described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0020] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other. The present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0021] According to an embodiment of the present disclosure, a method for information processing for container isolation is provided, such as Figure 1 As shown, including the following:
[0022] When building a container image, the container image is reinforced for security, including verifying the image source; building the image based on the preset image instructions; and processing the data in the container that is preset sensitive information. When the container is running, the reinforcement isolation is performed, including: configuring independent partitions for the container; configuring user groups for the container so that users in the user group can control the permissions of the container daemon; configuring audit rules for the container daemon to audit the container daemon based on the audit rules; and auditing the files and directories related to the container.
[0023] In this embodiment, the container security isolation technology is mainly aimed at the containers that build the cloud underlying infrastructure units. It can ensure that after the above method, the containers can effectively avoid the backdoor risks, sensitive information risks, unsafe software risks, etc. that exist during image construction and container operation, and achieve efficient isolation.
[0024] As an optional implementation of this embodiment, when verifying the image source, the trust mechanism of the container is configured to be enabled, wherein the image is digitally signed for data sent and received through the trust mechanism, and the digital signature is used to verify the image.
[0025] In this optional implementation, in order to ensure that the image content is trustworthy, it is recommended to enable the container's content trust mechanism. The content trust mechanism provides digital signatures for data sent to and received from remote image repositories. These signatures allow clients to verify the integrity and publisher of image tags. The content trust mechanism is disabled by default and can be completed by executing the following instructions or configuring it in the container's configuration file. export container_CONTENT_TRUST=1.
[0026] As an optional implementation of this embodiment, when building an image based on a preset image instruction, an instruction of local data can be preferentially called as the preset image instruction.
[0027] In this optional implementation, appropriate instructions should be selected when building an image. For example, if you need to introduce external files, do not use the ADD instruction in the container file if the COPY instruction can be used, because the COPY instruction only copies the file from the local host to the container file system, while the ADD instruction can download the file from the remote URL and perform operations such as decompression, which may bring the risk of adding malicious files from the URL.
[0028] As an optional implementation of this embodiment, processing the data belonging to preset sensitive information in the container includes: encrypting the preset sensitive information, and decrypting the data by a user who is authorized to use the encrypted data.
[0029] In this optional implementation, although the container assigns read-only permissions to users, sometimes users still need to be careful about the data stored in the container. For example, passwords, tokens, keys, and user confidential information cannot be stored in the container file. Even if these data are deleted after the container is created, it will cause risks because they can still be retrieved in the history of the image. It is recommended to use the encryption management functions of Kubernetes and container Swarm, which can effectively encrypt information, store it in an encrypted format, and can only be decrypted by authorized users when searching.
[0030] Furthermore, the image is lightweight and only necessary software packages are installed, which not only greatly helps in improving container performance, but more importantly reduces the attack surface.
[0031] In this embodiment, a separate partition is allocated for the storage of the container. By default, all container-related files are stored in the / var / lib / container directory. It is necessary to create a separate partition for the container as much as possible to ensure its security. For a newly installed container, you can audit it with the following command: grep / var / lib / container / etc / fstab.
[0032] When controlling the daemon process, the container daemon process requires root privileges, which provides full root access rights to users added to the container user group. Therefore, users in the container user group should be strictly restricted on the container host, and all untrusted users should be deleted.
[0033] As an optional implementation of this embodiment, after the container daemon process is audited based on the audit rules, the logs generated during the audit process are stored in a pre-created audit partition.
[0034] In this optional implementation, auditing the container daemon on the container requires auditing the activities and usage of the container daemon in addition to auditing the regular Linux file system and system calls. It is not audited by default. You can add audit rules through auditctl -w / usr / bin / Container -k Container, or update the rules by modifying the / etc / audit / audit.rules file. When auditing the container daemon, a large number of log files will be generated. To ensure regular log archiving, it is recommended to create a separate audit partition for log storage to avoid filling the root system with log files and affecting normal business.
[0035] As an optional implementation of this embodiment, before auditing the files and directories related to the container, the method further includes obtaining a target audit rule configured by the user to audit the files and directories related to the container based on the target audit rule.
[0036] In this optional implementation, when auditing container-related files and directories, in addition to auditing the container daemon, it is also necessary to audit container-related files and directories, such as / var / lib / container (containing all information about the container), / etc / container (containing all keys and certificates for TLS communication between the container daemon and the container client), container.service (container daemon running parameter configuration file), container.socket (the socket where the daemon runs), / etc / default / container (supports various parameters of the container daemon), / etc / default / daemon.json (supports various parameters of the container daemon), / usr / bin / container-containerd, / usr / bin / container-runc (container relies on containerd and runC to generate containers). The specific audit method is consistent with the audit of the daemon, and audit rules can be added through configuration files or command lines.
[0037] The container image security of this embodiment is in the continuous integration, continuous delivery and runtime protection stages, mainly to continuously evaluate and reinforce the container image to ensure security and non-tampering during the image generation, upload and distribution process. By adopting this container image security reinforcement solution, the risk of uncontrolled containers is eliminated from the source, and the backdoor risk, sensitive information risk, unsafe software risk, etc. in image construction are effectively avoided. Ensure that container computing, storage, and network resources are effectively isolated.
[0038] According to an embodiment of the present disclosure, a method for achieving high availability of services is also provided, including: after the container is deployed with the service, registering container information to the etcd storage component through the REST service; periodically querying the latest container information of the etcd storage component through the Confd configuration component, generating a Haproxy configuration file based on the latest container information, and automatically refreshing the Haproxy service.
[0039] In this embodiment, how the cloud platform built based on the container of the above embodiment and the services running on it can maintain long-term high availability for users and meet users' SLA requirements poses a challenge to traditional cloud platform technology. The method of this embodiment achieves high availability of cloud platform services.
[0040] refer to Figure 2To ensure high availability of services, it is not only necessary to quickly detect container or service failures, but also to provide a mechanism to quickly deploy or restart containers and services that have been detected to have failures, and ultimately restore the original service level.
[0041] This embodiment provides high availability guarantee of services based on the Haproxy+etcd+confd+Docker (HECD) architecture. The HECD architecture has the following advantages in providing high availability guarantee of services:
[0042] a) Automatic, real-time discovery and non-aware service refresh;
[0043] b) Support any number of Docker hosts;
[0044] c) Support multiple applications to access and distribute them to some hosts;
[0045] d) Using etcd to store information, the cluster supports high reliability;
[0046] f) Adopt confd configuration engine to support various access layers, such as using Nginx as reverse proxy;
[0047] g) Support load balancing, fault migration, etc.;
[0048] h) It has resource elasticity and can be scaled freely (achieved by generating and destroying containers).
[0049] In the HECD architecture, the system administrator first deploys the service on the container and starts and stops the container through the management system, and also registers the container information to the etcd storage component through the REST service, including the container name, host IP, mapped port, etc.; the Confd configuration component will periodically query the etcd component to obtain the latest container information, generate the Haproxy configuration file HaProxy.cfg according to the defined configuration template, and automatically refresh the Haproxy service. When users access business services, they are completely unaware of the online, offline, switching, and migration of the backend service, achieving the purpose of automatic discovery and high availability.
[0050] The above method can be used to quickly detect a component or service failure. The management service can discover the failure and update the status, indicating that the component can no longer provide the corresponding service, thereby reducing the possibility of application or service failure to a minimum. At the same time, the corresponding service can be restarted and restored as soon as possible, thereby providing service availability.
[0051] This embodiment also provides another method for achieving high availability of services, including: after the container is deployed with the service, registering container information to the etcd storage component through the REST service; periodically querying the latest container information of the etcd storage component through the Confd configuration component, generating a Haproxy configuration file based on the latest container information, and automatically refreshing the Haproxy service.
[0052] Compared with the above-mentioned embodiments, the method of this embodiment is applicable to any cloud platform constructed by containers.
[0053] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0054] The present disclosure provides an electronic device, such as Figure 3 As shown, the electronic device includes one or more processors 31 and a memory 32. Figure 3 A processor 31 is taken as an example.
[0055] The controller may further include: an input device 33 and an output device 34 .
[0056] The processor 31, the memory 32, the input device 33 and the output device 34 may be connected via a bus or other means. Figure 3 The example of connecting through bus is taken in the following.
[0057] The processor 31 may be a central processing unit (CPU). The processor 31 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the above chips. A general-purpose processor may be a microprocessor or the processor may be any conventional processor.
[0058] The memory 32 is a non-transitory computer-readable storage medium that can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the control method in the embodiment of the present disclosure. The processor 31 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions and modules stored in the memory 32, that is, the method of implementing the above method embodiment.
[0059] The memory 32 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of a processing device operated by the server, etc. In addition, the memory 32 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 32 may optionally include a memory remotely arranged relative to the processor 31, and these remote memories may be connected to a network connection device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0060] The input device 33 can receive input digital or character information, and generate key signal input related to user settings and function control of the processing device of the server. The output device 34 can include display devices such as a display screen.
[0061] One or more modules are stored in the memory 32, and when executed by one or more processors 31, the execution is as follows: Figure 1 The method shown.
[0062] Those skilled in the art can understand that the implementation of all or part of the processes in the above-mentioned embodiment method is a program that can be completed by instructing related hardware through a computer program, which can be stored in a computer-readable storage medium. When the program is executed, it can include the process of the embodiment of the above-mentioned method. Among them, the storage medium can be a disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk (Hard Disk Drive, abbreviated: HDD) or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above-mentioned types of memory.
[0063] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. An information processing method for container isolation, characterized in that: include: When building container images, perform security hardening on the container images, including verifying the image source; Build an image based on the preset image instructions; Processing the data in the container that is preset sensitive information; And reinforce isolation when the container is running, including: configuring independent partitions for containers; configuring user groups for containers so that users in the user groups can control the permissions of container daemons; configuring audit rules for container daemons to audit container daemons based on audit rules; and auditing files and directories related to containers.
2. The information processing method for container isolation according to claim 1, characterized in that: When verifying the image source, the trust mechanism of the container is configured to be enabled, wherein the image digitally signs the data sent and received through the trust mechanism, and the digital signature is used to verify the image.
3. The information processing method for container isolation according to claim 1, characterized in that: When building an image based on a preset image instruction, the instructions of local data can be preferentially called as the preset image instructions.
4. The information processing method for container isolation according to claim 1, characterized in that: Processing the data in the container that is preset sensitive information includes: encrypting the preset sensitive information, and decrypting the data by a user who is authorized to use the encrypted data.
5. The information processing method for container isolation according to claim 1, characterized in that: After the container daemon is audited based on the audit rules, the logs generated by the audit process are stored in the pre-created audit partition.
6. The information processing method for container isolation according to claim 1, characterized in that: Before auditing the files and directories related to the container, the method further includes obtaining a target audit rule configured by a user to audit the files and directories related to the container based on the target audit rule.
7. A method for achieving high service availability based on any one of the methods of claims 1 to 6, characterized in that: include: After the container is deployed, register the container information with the etcd storage component through the REST service; The Confd configuration component is used to periodically query the latest container information of the etcd storage component, generate the Haproxy configuration file based on the latest container information, and automatically refresh the Haproxy service.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes any one of claims 1-6.
Citation Information
Patent Citations
Security reinforcement method for credible container based on Docker
CN105069353A