Service deployment method and device, computer equipment and storage medium
By obtaining the deployment description file in the service deployment platform, generating proxy access requests and updating the description file, the deployment function provides platform proxy, solves the problem of self-development of service governance and observation functions in cloud-native applications, and realizes efficient provision of additional functions and platform integration.
Patent Information
- Application Number
- CN202311504339.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-10
- Publication Date
- 2025-05-13
AI Technical Summary
In cloud-native application scenarios, using only the container orchestration platform cannot quickly build large-scale applications, and users need to develop service governance and observation functions themselves, resulting in inefficiency.
By obtaining the service deployment description file, determine whether the function-providing platform proxy access conditions are met, generate the agent access request, update the deployment description file, and deploy the service and function-providing platform proxy in the slave node of the service deployment platform to realize additional functions out of the box.
It reduces the complexity provided by additional functions, improves the efficiency of additional functions, realizes the unconscious integration of the service deployment platform and the function providing platform, simplifies the initialization process, and improves user experience and freedom.
Smart Images

Figure CN119996188A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a service deployment method, apparatus, computer equipment and storage medium. Background Art
[0002] With the development of science and technology, container orchestration platforms have emerged. Container orchestration platforms refer to platforms that provide container orchestration, scheduling, and deployment. For example, container orchestration platforms can be specifically kubernetes (abbreviated as K8s) platforms.
[0003] However, in the scenario of cloud-native applications, using only the container orchestration platform cannot quickly build a large-scale application. Generally speaking, an application can be split into a set of independent services, each of which can be independently developed, tested, deployed, and expanded. The container orchestration platform only provides basic service deployment functions. For additional functions such as service governance and service observation required for service operation, users need to develop them themselves, which increases the complexity of providing additional functions for services and reduces the efficiency of providing additional functions for services. Summary of the invention
[0004] Based on this, it is necessary to provide a service deployment method, apparatus, computer device, computer-readable storage medium and computer program product that can improve the efficiency of providing additional functions in response to the above technical problems.
[0005] In a first aspect, the present application provides a service deployment method, the method comprising:
[0006] Obtaining a deployment description file of a service, wherein the deployment description file records configuration information required to deploy the service;
[0007] In the case where it is determined according to the deployment description file that the service meets the proxy access condition of the function providing platform, generating a proxy access request according to the deployment description file;
[0008] Sending the proxy access request to the function providing platform, wherein the sent proxy access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file;
[0009] Based on the new deployment description file returned by the function providing platform, the deployment of the service and the function providing platform agent in the slave node of the service deployment platform is triggered.
[0010] In a second aspect, the present application further provides a service deployment device, the device comprising:
[0011] The request generation module is used to obtain a deployment description file of a service, wherein the deployment description file records configuration information required to deploy the service; when it is determined according to the deployment description file that the service meets the agent access conditions of the function providing platform, an agent access request is generated according to the deployment description file.
[0012] The new file generation module is used to send the agent access request to the function providing platform, and the sent agent access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file.
[0013] The deployment implementation module is used to trigger the deployment of the service and the function providing platform agent in the slave node of the service deployment platform based on the new deployment description file returned by the function providing platform.
[0014] In one of the embodiments, the service deployment device also includes an initialization module, which is used to receive an initialization request issued by the function providing platform; in response to the initialization request, a platform operation component is created and an access control callback function is added; the platform operation component is used to transmit requests with the function providing platform; the access control callback function is implemented through an access control callback function, and the access control callback function is a function used to implement custom control logic in the process of generating a new deployment description file.
[0015] In one of the embodiments, the initialization request sent by the function providing platform is a request generated by a resource management service in the function providing platform in response to an initialization type selection operation, and based on the initialization type selection operation, when determining to execute the first initialization process, a request is generated according to the metadata of the function providing platform.
[0016] In one of the embodiments, the initialization module is also used to receive an initialization request sent by a request forwarding service of the function provision platform through an interface server in the master node of the service deployment platform; wherein the interface server is a server for receiving and processing requests and for managing resource objects in the slave nodes of the service deployment platform; and the request forwarding service is a service that communicates with a resource management service in the function provision platform and receives an initialization request generated by the resource management service.
[0017] In one of the embodiments, the initialization module is also used to obtain the image of the access control callback function and the platform operation component in response to the initialization request; add a new platform operation component through the image of the platform operation component, and add the access control callback function in the interface server in the main node of the service deployment platform through the access control callback function.
[0018] In one of the embodiments, the service deployment device further includes an initialization module for receiving an initialization file provided by the function providing platform; creating a platform operation component and adding an access control callback function through the initialization file.
[0019] In one of the embodiments, the initialization file is input into the service deployment platform by an administrator of the service deployment platform; the initialization file obtained by the administrator of the service deployment platform is a file that triggers a request for transit service feedback in the function providing platform when a resource management service in the function providing platform responds to an initialization type selection operation and determines to execute a second initialization process based on the initialization type selection operation.
[0020] In one of the embodiments, the request generation module is also used to obtain a first preset tag, and match the tag recorded in the deployment description file with the first preset tag to obtain a first matching result; when it is determined according to the first matching result that the recorded tag contains a first matching tag that matches the first preset tag, the value of the first matching tag is obtained; when the value of the first matching tag is a preset target value, it is determined that the service meets the function providing platform agent access conditions.
[0021] In one of the embodiments, the request generation module is also used to determine the namespace to which the service is to be deployed based on the namespace identifier recorded in the deployment description file, and obtain the namespace to be deployed; obtain the label of the namespace to be deployed; obtain a second preset label, and match the label of the namespace to be deployed with the second preset label to obtain a second matching result; when it is determined based on the second matching result that the label of the namespace to be deployed has a second matching label that matches the second preset label, obtain the value of the second matching label; when the value of the second matching label is the preset target value, determine that the service meets the function providing platform agent access conditions.
[0022] In one of the embodiments, the main node of the service deployment platform includes a platform operation component and an interface server, and the interface server has an access control callback function;
[0023] The request generation module is also used to generate an initial proxy access request carrying the deployment description file through the interface server and based on the access control callback function when it is determined that the service meets the proxy access conditions of the function providing platform, and send the initial proxy access request to the platform operation component; through the platform operation component, generate a proxy access request based on the initial proxy access request and a preset digital certificate.
[0024] In one of the embodiments, the function providing platform includes a request forwarding service and a resource management service; the proxy access request sent is used to trigger the request forwarding service to authenticate the platform operation component based on the digital certificate carried by the proxy access request, and send the proxy access request to the resource management service after the verification is passed, so that the resource management service responds to the proxy access request, adds the configuration information required for deploying the function providing platform agent in the deployment description file, and obtains a new deployment description file.
[0025] In one of the embodiments, the new file generation module is also used to identify the operation type corresponding to the proxy access request through the platform operation component; the operation type is a type that characterizes the operation on the deployment description file; when the operation type corresponding to the proxy access request is the target operation type, the proxy access request is sent to the function provision platform through the platform operation component.
[0026] In one of the embodiments, the function providing platform includes a resource management service; the agent access request sent is used to trigger the resource management service to obtain the address of the image of the function providing platform agent and the environment variables required to deploy the function providing platform agent, and add the address and the environment variables to the deployment description file to obtain a new deployment description file.
[0027] In one of the embodiments, the deployed function providing platform agent is used to interact with the function providing platform to provide additional functions different from the native functions provided by the service deployment platform for the service; the additional functions include at least one of managing the life cycle of the deployed service, performing service governance on the deployed service, or observing the deployed service.
[0028] In a third aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of any one of the service deployment methods provided in the embodiments of the present application are implemented.
[0029] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any service deployment method provided in the embodiments of the present application are implemented.
[0030] In a fifth aspect, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of any service deployment method provided in the embodiments of the present application.
[0031] The above-mentioned service deployment method, apparatus, computer equipment, storage medium and computer program product can determine whether the service meets the proxy access conditions of the function providing platform based on the deployment description file by obtaining the deployment description file of the service. By determining whether the service meets the proxy access conditions of the function providing platform, a proxy access request can be generated only when the proxy access conditions of the function providing platform are met, thereby reducing the computer and other resources consumed by generating unnecessary proxy access requests. By generating a proxy access request, the proxy access request can be sent to the function providing platform, so that the function providing platform can update the deployment description file according to the configuration information required to deploy the function providing platform, obtain a new deployment description file, and return the new deployment description file to the service deployment platform. By receiving the new deployment description file returned by the function providing platform, the service and the function providing platform agent can be deployed based on the new deployment file. Since the function providing platform agent is an agent of the function providing platform, and the function providing platform is a platform for providing additional functions, the present application can achieve the purpose of providing the service with out-of-the-box additional functions based on the function providing platform agent by deploying a function providing platform agent for the service while deploying the service. Compared with the traditional method of providing additional functions for services deployed in the service deployment platform through manual programming, the present application greatly reduces the complexity of providing additional functions, thereby improving the efficiency of providing additional functions. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 An application environment diagram of a service deployment method in an embodiment;
[0033] Figure 2 A schematic diagram of a process flow of a service deployment method in an embodiment;
[0034] Figure 3 A schematic diagram of a service deployment cluster in one embodiment;
[0035] Figure 4 A schematic diagram of providing platform agent deployment for services and functions in one embodiment;
[0036] Figure 5 A schematic diagram of an initialization page in one embodiment;
[0037] Figure 6 is a schematic diagram of an initialization result in one embodiment;
[0038] Figure 7 It is a schematic diagram of the interaction of the first initialization in one embodiment;
[0039] Figure 8 It is a schematic diagram of the interaction of the second initialization in one embodiment;
[0040] Fig. 9 is a schematic diagram of a label in a whitelist mode in an embodiment;
[0041] Fig.10 A schematic diagram of a label in a blacklist mode in an embodiment;
[0042] Fig.11 A schematic diagram of deployment interaction in one embodiment;
[0043] Fig.12 It is a flowchart of a service deployment method in a specific embodiment;
[0044] Fig.13 It is a schematic diagram of the overall framework of a service deployment method in one embodiment;
[0045] Fig.14 It is a structural block diagram of a service deployment device in one embodiment;
[0046] Fig.15 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0048] The service deployment method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the server cluster 102 communicates with the server cluster 104 through the network, and the server cluster 104 communicates with the terminal 106 through the network. The data storage system can store the data that the server cluster 102 and the server cluster 104 need to process. The data storage system can be integrated on the server cluster 102 and the server cluster 104, or it can be placed on the cloud or other servers. The server cluster 102 can receive the deployment description file of the service to be deployed, and send the deployment description file to the server cluster 104, so that the server cluster 104 adds the configuration information required for the deployment function providing platform agent in the deployment description file, obtains the new deployment description file, and returns the new deployment description file to the server cluster 102. The server cluster 102 can deploy the service to be deployed and deploy the function providing platform agent according to the new deployment description file, so that when the deployed service is running, the function providing platform agent can manage the deployed service and return the management result to the terminal 106 for display. Among them, the terminal 106 can be, but is not limited to, various desktop computers, laptops, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The servers in the server cluster 102 can be multiple independent servers. The servers in the server cluster 104 and the server cluster 102 can be independent physical servers, or they can be server clusters or distributed systems composed of multiple physical servers, or they can be cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0049] The present application relates to cloud technology. For example, the server of the present application may be a cloud server. Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and network in a wide area network or a local area network to realize the calculation, storage, processing, and sharing of data. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model application. It can form a resource pool, which is used on demand and is flexible and convenient. Cloud computing technology will become an important support. The background services of the technical network system require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. With the high development and application of the Internet industry, each item may have its own identification mark in the future, and all need to be transmitted to the background system for logical processing. Data of different levels will be processed separately, and all kinds of industry data require strong system backing support, which can only be achieved through cloud computing.
[0050] It should be noted that the words "first", "second" and similar terms used in this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Unless the context clearly indicates otherwise, the singular form "one", "an" or "the" and similar terms do not indicate a quantity restriction, but rather indicate the presence of at least one. The quantities of "multiple" or "multiple copies" mentioned in the various embodiments of the present application all refer to the quantity of "at least two", for example, "multiple" refers to "at least two", and "multiple copies" refers to "at least two copies".
[0051] In one embodiment, Figure 2 As shown, a service deployment method is provided, which is applied to Figure 1 Taking the master node in the server cluster 102 in the example as an example, the following steps are included:
[0052] Step 202: Obtain a deployment description file of the service. The deployment description file records configuration information required to deploy the service.
[0053] Among them, the service deployment platform can be regarded as a service deployment system, which is a platform implemented by a master node and multiple slave nodes. The control plane component runs on the master node, and the master node and multiple slave nodes together constitute a service deployment cluster. Services can be deployed through the service deployment platform. When services are deployed through containers, the service deployment platform can be specifically a container orchestration platform. When services are deployed through containers, the service deployment cluster can be specifically a container cluster, and services or applications can be deployed in containers in the container cluster, and the control plane component can be used to ensure that the services and applications in the container cluster can work as expected. For example, refer to Figure 3 The control plane component stores information about the service deployment cluster. When the control plane component receives a service deployment request, the control plane component can trigger the service deployment cluster to deploy the service in the container according to the service deployment request. Each slave node of the service deployment cluster can have a minimum deployable unit pod, which can be regarded as a collection of one or more containers that share the same network and storage space for deploying services. In one embodiment, the control plane component can also be used to manage other components and allocate pods to different nodes in the service deployment cluster based on the resource requirements and availability of the pods. Figure 3 A schematic diagram of a service deployment cluster in an embodiment is shown.
[0054] Among them, the service deployment platform is a platform for performing deployment and operation operations for the IAAS (Infrastructure as a Service) layer. The IAAS layer is the infrastructure as a service layer, which refers to a service model that provides Internet infrastructure as a service to the outside world through the network. In this service model, ordinary users do not need to build a data center or other hardware facilities by themselves, but obtain computer infrastructure services from IAAS service providers through the Internet through leasing, including servers, storage, and network services. Since the service deployment platform is an IAAS-oriented platform, the service deployment platform has a strong customizable service deployment capability for native deployment. However, since the service deployment platform is a platform for performing deployment and operation operations for the IAAS layer, the service deployment platform can only provide basic service deployment capabilities. For capabilities such as service governance, service lifecycle management, and service observability, users need to implement them through additional programming.
[0055] Specifically, when a user wants to deploy a service, the user can input the deployment description file of the service through the front-end page of the service deployment platform, so that the front-end page can send the input deployment description file to the control plane component. The deployment description file is a file that records the configuration information required to deploy the service. For example, the deployment description file can record the service's identifier, name, storage address of the service image, environmental parameters required for service deployment, etc. Among them, a service refers to a program, routine or process that performs a specified system function in order to support other programs.
[0056] In one embodiment, the control plane component may include an interface server, and the control plane component may receive the deployment description file through the interface server. The interface server is a module that provides the add, delete, modify, and query interface for various resource objects (pod, RC, Service, etc.) in the service deployment platform, and is the data bus and data center of the entire service deployment platform. The interface server can be specifically implemented through the interface server.
[0057] Step 204: when it is determined according to the deployment description file that the service meets the proxy access condition of the function providing platform, a proxy access request is generated according to the deployment description file.
[0058] Specifically, when the control plane component receives the deployment description file, the control plane component can determine whether it is necessary to provide a platform agent for the service access function based on the deployment description file, so as to include the service into the management of the function providing platform based on the accessed function providing platform agent. If it is determined that it is necessary to provide a platform agent for the service access function, the control plane component generates an agent access request according to the deployment description file. For example, when the deployment description file A of service A is received and it is determined based on the deployment description file A that service A meets the function providing platform agent access conditions, the control plane component generates an agent access request based on the deployment description file A, so that the function providing platform agent corresponding to service A can be deployed based on the agent access request.
[0059] The function providing platform agent refers to a component used to interact with the function providing platform to provide additional services. The function providing platform is a platform oriented to the PAAS (Platform as a Service) layer. For example, the function providing platform can be a microservice platform. PaaS refers to a model that provides a server platform as a service. The function providing platform agent refers to an agent service provided by the function providing platform. Through the service platform agent, the service management function provided by the function providing platform can be used.
[0060] Since the function providing platform is a PaaS-oriented platform, it provides users with middleware and service governance and observability capabilities out of the box. Although the function providing platform provides users with middleware and service governance and observability capabilities out of the box, while providing convenience, the function providing platform also brings constraints to users' use, including: poor service deployment customization capabilities, and the deployment process completely depends on the definition method of the function providing platform; high resource management attribute requirements, the underlying cluster needs to be fully hosted on the function providing platform, resulting in a strong binding between the service deployment platform and the function providing platform. In a hybrid cloud scenario, there may be incompatibility issues between the permissions of the service deployment platform and the function providing platform; some capabilities are missing, and the use of the function providing platform blocks the strong customizable service deployment capabilities of native deployment. Therefore, the purpose of this application is to realize an innovative deployment connection method, to complete the integration of the function providing platform and the service deployment platform in an imperceptible way, so that users can not only deploy services in the service deployment platform in the way of native deployment services, but also because the function providing platform and the service deployment platform are integrated, the additional functions provided by the function providing platform can also be provided for the deployed services, such as providing service governance, service lifecycle management and other functions.
[0061] In one of the embodiments, when uploading a deployment description file, the user can specify whether a platform agent needs to be provided for the service access function according to his or her own needs. When the user specifies that a platform agent needs to be provided for the service access function, it is determined that the service meets the platform agent access conditions for providing the function. Otherwise, it is determined that the service does not meet the platform access conditions for providing the function.
[0062] In one embodiment, the control plane component includes an interface server, and an access control callback function is set in the interface server. Through the access control callback function, a proxy access request can be generated when it is determined that the service meets the proxy access condition of the function providing platform. The access control callback function is a function used to implement custom control logic in the process of generating a new deployment description file.
[0063] In one embodiment, when a service does not meet the access proxy condition of the function providing platform, the control plane component sends the deployment description file of the service to the service deployment cluster, that is, to the slave node of the service deployment platform, so that the slave node of the service deployment platform deploys the service according to the deployment description file. For example, the node in the service deployment cluster can create a container according to the deployment description file and deploy the service into the container.
[0064] Step 206: Send the proxy access request to the function providing platform. The sent proxy access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file.
[0065] Specifically, the control plane component may send a proxy access request to the function providing platform. When the function providing platform receives the proxy access request, the function providing platform may obtain the configuration information required for deploying the function providing platform agent, and update the deployment description file according to the configuration information required for deploying the function providing platform, and obtain a new deployment description file. For example, the function providing platform may determine the corresponding update rule according to the correspondence between the configuration information and the update rule, and update the deployment description file through the corresponding update rule. Alternatively, the function providing platform directly writes the configuration information required for deploying the function providing platform agent into the deployment description file to obtain a new deployment description file. For the convenience of description, the new deployment description file is referred to as a new deployment description file below. For example, the function providing platform may obtain the identifier of the function providing platform agent, the storage address of the image of the function providing platform agent, the environment parameters required when deploying the function providing platform agent, and other information, and record the obtained information in the received deployment description file to obtain a new deployment description file.
[0066] In one embodiment, the control plane component includes a platform operation component, which is used to communicate with the interface server and transparently transmit the proxy access request to the function providing platform. In software development, a component refers to a modular unit with independent functions and reusability. It can be part of a software system or an independent software unit.
[0067] In one embodiment, the function providing platform includes a request relay service and a resource management service. The platform operation component in the control plane component can send an agent access request to the request relay service in the function providing platform, so that the request relay service can send the agent access request to the resource management service, so that the resource management service responds to the agent access request, adds the configuration information required for deploying the function providing platform agent in the deployment description file, and obtains a new deployment description file. Among them, the request relay service is responsible for communicating with the platform operation component and the resource management service to prevent external users from directly accessing the resource management service. The resource management service is a service used to manage the meta information of the function providing platform.
[0068] Step 208: Based on the new deployment description file returned by the function providing platform, trigger the deployment of services and function providing platform agents in the slave nodes of the service deployment platform.
[0069] Among them, native functions are out-of-the-box functions provided by the service deployment platform, such as container orchestration function, container scheduling function, etc. Additional functions are out-of-the-box functions provided by the function provision platform, such as service governance function, service lifecycle management function, service observation function, etc.
[0070] Specifically, when the function providing platform generates a new deployment description file, the function providing platform can return the new deployment description file to the control plane component, so that the control plane component can trigger the deployment of the service and function providing platform agent based on the new deployment description file. For example, the control plane component can trigger the idle nodes in the service deployment cluster to deploy the service and function providing platform agent based on the new deployment description file.
[0071] In one of the embodiments, the service and the function providing platform agent can be deployed in the same node in the service deployment cluster. For example, when the new deployment description file contains the configuration information required for deploying service A and the configuration information required for deploying the function providing platform agent, the service A and the function providing platform agent can be deployed on the same idle node according to the configuration information required for deploying service A and the configuration information required for deploying the function providing platform agent recorded in the new deployment description file. It is easy to understand that when there are multiple services, the function providing platform agent corresponding to each service can be deployed, so that different function providing platform agents can be used to collect different service operation information, and manage different services based on the collected operation information.
[0072] In one embodiment, reference Figure 4 , the control plane component on the service deployment platform side can send the proxy access request to the function provision platform, so that the function provision platform can generate a new deployment description file in response to the proxy access request and return the new deployment description file to the control plane component. When the control plane component receives the new deployment description file, the control plane component can trigger the service deployment cluster to deploy the service and the function provision platform agent based on the new deployment description file. Figure 4 A schematic diagram showing the deployment of a service and function providing platform agent in one embodiment.
[0073] In one of the embodiments, the deployed function providing platform agent is used to interact with the function providing platform to provide additional functions that are different from the native functions provided by the service deployment platform for the service. When the service and the function providing platform agent are deployed in the service deployment cluster, the function providing platform can provide out-of-the-box management functions for the service based on the function providing platform agent. For example, at least one of service governance capabilities, configuration management capabilities, and service observability capabilities is provided to the service. Exemplarily, when the deployed service is running, the function providing platform agent can collect the operation information of the service, and generate an operation log based on the collected operation information, and send the operation log to the function providing platform, so that the user can view the operation log through the function providing platform. For another example, when the deployed service runs abnormally, the function providing platform can restart the abnormally running service and send the abnormal operation status to the function providing platform so that the user can view the abnormal operation status through the function providing platform.
[0074] In the above service deployment method, by obtaining the deployment description file of the service, it is possible to determine whether the service meets the proxy access conditions of the function providing platform based on the deployment description file. By determining whether the service meets the proxy access conditions of the function providing platform, a proxy access request can be generated only when the proxy access conditions of the function providing platform are met, thereby reducing the computer and other resources consumed by generating unnecessary proxy access requests. By generating a proxy access request, the proxy access request can be sent to the function providing platform, so that the function providing platform can update the deployment description file according to the configuration information required to deploy the function providing platform, obtain a new deployment description file, and return the new deployment description file to the service deployment platform. By receiving the new deployment description file returned by the function providing platform, the service and the function providing platform agent can be deployed based on the new deployment file. The function providing platform agent is an agent of the function providing platform, and the function providing platform is a platform for providing additional functions. Therefore, the present application can achieve the purpose of providing the service with out-of-the-box additional functions based on the function providing platform agent by deploying a function providing platform agent for the service while deploying the service. Compared with the traditional method of providing additional functions for services deployed in the service deployment platform through manual programming, the present application greatly reduces the complexity of providing additional functions, thereby improving the efficiency of providing additional functions.
[0075] In one of the embodiments, the above method also includes an initialization step, which includes: receiving an initialization request issued by a function providing platform; in response to the initialization request, creating a platform operation component and adding an access control callback function; the platform operation component is used to transmit requests between the function providing platform; the access control callback function is implemented through an access control callback function, which is a function used to implement custom control logic in the process of generating a new deployment description file.
[0076] Specifically, before the service is deployed, an initialization process needs to be executed. The initialization process includes a first initialization process and a second initialization process. When the first initialization process needs to be executed, the function providing platform can generate an initialization request and send the initialization request to the service deployment platform, for example, the initialization request is sent to the control plane component of the service deployment platform. When the control plane component receives the initialization request issued by the function providing platform, the control plane component can respond to the initialization request, create a platform operation component in the master node, and add an access control callback function. Among them, the platform operation component can be used to transmit requests between the function providing platform, and the platform operation component can directly communicate with the interface server in the master node. Therefore, the platform operation component serves as a bridge for communication between the interface server and the function providing platform. The access control callback function is implemented through an access control callback function, which can be a function customized by a user according to needs, which can be used to implement specific control logic in the initialization process. The present application can utilize the access control callback function to implement a reverse control request triggered from the service deployment platform to the function provision platform, thereby triggering the operation of the function provision platform through the service deployment platform. For example, the control callback function can be utilized to trigger the function provision platform through the service deployment platform to add some configuration information to the deployment description file to obtain a new deployment description file.
[0077] In this embodiment, the first initialization process can be regarded as a fully automatic initialization process. Through the fully automatic initialization process, the initialization operation can be automatically performed to achieve an imperceptible automation process. This not only improves the convenience of initialization, but also improves the user experience.
[0078] In one of the embodiments, the initialization request sent by the function providing platform is a request generated by a resource management service in the function providing platform in response to an initialization type selection operation, and based on the initialization type selection operation, when determining to execute the first initialization process, a request is generated according to the meta-information of the function providing platform.
[0079] Specifically, the initialization request sent by the function provision platform to the service deployment platform is obtained in response to the initialization type selection operation. Figure 5, the front-end page of the function providing platform may display an initialization page, and the initialization page may display an initialization operation type selection control, and the initialization operation type selection control may specifically be a first type control 501 and a second type control 502. When the user clicks the first type control 501, it can be considered that the user expects to execute the first initialization process; when the user clicks the second type control 502, it can be considered that the user expects to execute the second initialization process. The operation of the user clicking the initialization operation type selection control is called the initialization type selection operation. The resource management service in the function providing platform can respond to the initialization type selection operation. When it is determined that the user expects to execute the first initial process, the resource management service can obtain the meta information of the function providing platform and generate an initialization request based on the meta information of the function providing platform. Among them, the meta information of the function providing platform refers to the information used to describe the function providing platform. For example, the meta information of the function providing platform includes the name, logo and other information of the function providing platform. Figure 5 A schematic diagram of an initialization page in an embodiment is shown.
[0080] In this embodiment, by displaying the initialization page, the user can freely select the initialization type based on the initialization page, thereby greatly improving the flexibility of initialization. In addition, the initialization request is generated through the meta information of the function providing platform, so that the service deployment platform that receives the initialization request can understand the basic information of the function providing platform based on the meta information in the initialization request, and thus perform subsequent operations based on the basic information of the function providing platform. For example, when the function providing platform is determined to be an illegal platform based on the basic information of the function providing platform, the initialization operation can be suspended.
[0081] In one of the embodiments, receiving an initialization request sent by a function providing platform includes: receiving an initialization request sent by a request forwarding service of the function providing platform through an interface server in a master node of the service deployment platform; wherein the interface server is a server for receiving and processing requests and for managing resource objects in slave nodes of the service deployment platform; and the request forwarding service is a service that communicates with a resource management service in the function providing platform and receives an initialization request generated by the resource management service.
[0082] Specifically, when the resource management service of the function provision platform generates an initialization request, the resource management service can send the initialization request to the request relay service in the function provision platform, and then send the initialization request to the interface server in the service deployment platform through the request relay service. The interface server can then create a platform operation component based on the initialization request and add an access control callback function.
[0083] In one of the embodiments, since the service deployment platform can be implemented through a service deployment cluster, before performing the initialization operation, the service deployment cluster can be imported into the function provision platform. For example, the service deployment cluster can be registered with the function provision platform so that the subsequent function provision platform can determine the service deployment cluster to which the initialization request needs to be sent based on the registration information.
[0084] In the above embodiment, since the request relay service is a service that isolates external direct access to the resource management service, the initialization request generated by the resource management service is sent to the service deployment platform through the request relay service, which can isolate the direct connection between the service deployment platform and the resource management service, thereby improving the security of the resource management service. Since the resource management service contains meta-information, by improving the security of the resource management service, the security of the meta-information can also be improved, reducing the risk of meta-information leakage. In addition, since the interface server is the native server of the service deployment platform for receiving external requests, the purpose of utilizing the native functions of the service deployment platform can be achieved by setting the interface server to receive the initialization request, thereby improving the utilization rate of the native functions.
[0085] In one of the embodiments, in response to an initialization request, a creation function provides a platform operation component and adds an access control callback function, including: in response to the initialization request, obtaining an image of the access control callback function and the platform operation component; adding a new platform operation component through the image of the platform operation component, and adding an access control callback function in the interface server in the main node of the service deployment platform through the access control callback function.
[0086] Specifically, when the interface server in the service deployment platform receives an initialization request, the interface server may obtain the access control callback function and the image of the platform operation component in response to the initialization request. The interface server may create a platform operation component in the main node of the service deployment platform through the image of the platform operation component, and add an access control callback function in the interface server by obtaining the obtained control callback function. For example, the initialization request may carry the storage address of the access control callback function, the storage address of the image of the platform operation component, and the configuration file of the platform operation component, so that the interface server may obtain the image of the platform operation component and the access control callback function based on the storage address carried by the initialization request, and according to the configuration file of the platform operation component and the image of the platform operation component, add a platform operation component for communicating with the interface server in the main node, and according to the access control callback function, write the access control callback function into the interface server, so that the interface server may implement the access control callback function through the written access control callback function.
[0087] In one embodiment, reference Figure 6,After the initialization operation is performed, compared to the original service deployment platform, a ,platform operation component is added to the control plane component of the ,service deployment platform, and an access control callback function is written in the ,interface server. Figure 6 A schematic diagram showing an initialization result in an embodiment is shown.
[0088] In one embodiment, reference Figure 7 , Figure 7 An interactive schematic diagram of the first initialization in an embodiment is shown. The first initialization process involves a resource management service of a function providing platform, a request transfer service of the function providing platform, and an interface server of a service deployment platform. The user performs an initialization operation on the function providing platform. First, the resource management service prepares metadata information of the function providing platform for the initialization operation, and then generates an initialization request based on the prepared metadata information, and sends the initialization request to the actual control plane of the function providing platform, that is, to the request transfer service. After receiving the initialization request, the request transfer service will prepare a digital certificate for the service deployment platform, and send the digital certificate and the initialization request to the interface server of the service deployment platform. Then the interface server can create a platform operation component in the main node of the service deployment platform based on the initialization request and add a corresponding access control callback function in the interface server. After the service deployment platform creates the platform operation component and adds the access control callback function, the request transfer service returns the operation success to the resource management service, and in the end process, the resource management service records the meta information of the service deployment platform. Among them, the request transfer service service deployment platform prepares a digital certificate, which can be used to verify the identity of the platform operation component later. The recorded meta information of the service deployment platform can be used to subsequently manage the services deployed in the service deployment platform.
[0089] In the above embodiment, the user only needs to perform simple operations to implement the initialization operation, thereby greatly reducing the complexity of initialization and improving the efficiency of initialization.
[0090] In one of the embodiments, the method further includes an initialization step, which includes: receiving an initialization file provided by a function providing platform; creating a platform operation component and adding an access control callback function through the initialization file.
[0091] Specifically, before deploying the service, an initialization process needs to be executed. The initialization process includes a first initialization process and a second initialization process. When executing the second initialization process, the function provision platform can provide an initialization file, so that when the service deployment platform receives the initialization file, the initialization process can be completed through the initialization file. For example, the service deployment platform can create a platform operation component in the control plane component in the master node through the initialization file, and add an access control callback function in the interface server. Among them, the initialization file records some configuration information required for initialization, such as information such as the mirror storage address of the platform operation component.
[0092] In one of the embodiments, the initialization file is input into the service deployment platform by the administrator of the service deployment platform; the initialization file obtained by the administrator of the service deployment platform is a file that responds to the initialization type selection operation through the resource management service in the function provision platform, and triggers the request transfer service feedback in the function provision platform when it is determined to execute the second initialization process based on the initialization type selection operation.
[0093] Specifically, before receiving the initialization file provided by the function providing platform, the administrator of the service deployment platform can review the initialization file. When the review is passed, the administrator can input the initialization file into the service deployment platform, and the service deployment platform will perform the initialization operation based on the initialization file. The review content can be freely set according to the needs, and the security of initialization can be improved through the review.
[0094] The initialization file obtained by the administrator is provided by the function provider platform. For example, refer to Figure 5 , the front-end page of the function providing platform may display an initialization page, and the initialization page may display an initialization operation type selection control, and the initialization operation type selection control may specifically be a manual type control 501 and an automatic type control 502. When the user clicks the manual type control 501, it can be considered that the user expects to execute the second initialization process; at this time, when the resource management service in the function providing platform determines that the user expects to execute the second initialization process, it triggers the request transfer service to generate an initialization file, so that the resource management service can receive the initialization file generated by the request transfer service, and provide the initialization file generated by the request transfer service for the user to download. For example, the resource management service can generate an initialization file generation request, and send the initialization file generation request to the request transfer service, so that the request transfer service can respond to the initialization file generation request to generate an initialization file. When the resource management service receives the initialization file generated by the request transfer service, the resource management service can trigger the front-end of the function providing platform to display a prompt message indicating that the initialization file has been successfully generated, so that the user can download the initialization file through the initialization file download control.
[0095] In one embodiment, reference Figure 8 , Figure 8 An interactive schematic diagram of the second initialization in an embodiment is shown. The second initialization process includes a resource management service of a function providing platform, a request transfer service of the function providing platform, and a service deployment platform. When the resource management platform determines that the user expects to execute the second initialization process, the resource management platform may send an initialization request to the request transfer service, so that the request transfer service responds to the initialization request, creates or obtains an initialization file, and returns the initialization file to the resource management platform, which is fed back to the user by the resource management platform. For the convenience of description, the initialization request generated in the first initialization process may be referred to as the first initialization request, and the initialization request generated in the second initialization process may be referred to as the second initialization request. After the user receives the initialization file, the user may transfer the initialization file to the administrator of the service deployment platform, and the administrator of the service deployment platform will review the initialization file, and after the review is passed, it will be input into the service deployment platform, so that the service deployment platform can be initialized based on the initialization file.
[0096] In the above embodiment, the service deployment platform only needs to receive an initialization file to implement the initialization process based on the initialization file, thereby simplifying the complexity of initialization and improving the efficiency of initialization. In addition, since the administrator manually inputs the initialization file into the service deployment platform, even in the case of authority isolation between the service deployment platform and the function provision platform, the service deployment platform can still complete the initialization process based on the manually input initialization file.
[0097] In addition, since the present application provides multiple initialization methods, the flexibility of initialization is greatly improved.
[0098] In one of the embodiments, the step of determining whether a service satisfies the function providing platform agent access conditions based on a deployment description file includes: obtaining a first preset tag, and matching the tag recorded in the deployment description file with the first preset tag to obtain a first matching result; when it is determined based on the first matching result that the recorded tag contains a first matching tag that matches the first preset tag, obtaining the value of the first matching tag; when the value of the first matching tag is a preset target value, determining that the service satisfies the function providing platform agent access conditions.
[0099] Specifically, since not all services require access functions to provide a platform agent, for example, when there is no need to manage a service, there is no need to provide a platform agent for the service access function. Therefore, this application provides a whitelist mode and a blacklist mode, through which services that require access functions to provide a platform agent can be customized.
[0100] More specifically, for the whitelist mode, when the service deployment platform receives the deployment description file of the service, the service deployment platform can obtain a preset first preset tag, and match the tag recorded in the deployment description file with the first preset tag to determine whether a tag matching the first preset tag is recorded in the deployment description file. For the convenience of description, the tag that matches the first preset tag in the whitelist mode is referred to as the first matching tag. For example, when a tag is the same or similar to the first preset tag, it can be determined that the tag matches the first preset tag. When it is determined that there is a first matching tag in the deployment description file, the service deployment platform obtains the value of the first matching tag. When the value of the first matching tag is the preset target value, it is considered that the service with the deployment description file meets the function provision platform agent access conditions, and it is subsequently necessary to provide a platform agent for the service access function.
[0101] In one embodiment, reference Fig. 9 When the user expects to provide a platform agent for access to service A, that is, when the user expects to include service A in the management scope of the function providing platform, the tag "tsf.tenxxxcloud.com / inject" can be written in advance in the deployment description file of service A. It is easy to understand that the tag written is a tag that is consistent with the first preset tag. After writing the tag "tsf.tenxxxcloud.com / inject", the value of the tag can also be set to a target value, for example, to "enable", so that when the service deployment platform detects that there is a tag "tsf.tenxxxcloud.com / inject" in the deployment description file and the value of the tag is "enable", it is determined that service A meets the access conditions of the function providing platform agent, and it is necessary to access a function providing platform agent for service A in the future, so as to include service A in the management scope of the function providing platform through the accessed function providing platform agent, and then the additional functions provided by the function providing platform, such as management functions, can be used for service A in the future. Fig. 9 A schematic diagram of a tag in a whitelist mode in one embodiment is shown.
[0102] It is easy to understand that when the first matching tag does not exist in the deployment description file, or the value of the first matching tag is not the target value, for example, when the value of the tag "tsf.tenxxxcloud.com / inject" is "disable", it is determined that service A does not meet the function provision platform agent access conditions. At this time, the service deployment platform directly deploys service A based on the deployment description file.
[0103] In one embodiment, an interface server in a service deployment platform may be used to check whether a first matching tag exists in a deployment description file and whether a value of the first matching tag is a target value.
[0104] In the above embodiment, by adding a tag to the deployment description file, it is possible to determine whether the service needs to access the function provider platform agent based on the tag, thereby greatly simplifying the complexity of determining whether the service needs to access the function provider platform agent and improving the efficiency of determining whether the service needs to access the function provider platform agent.
[0105] In one of the embodiments, the method further includes: determining the namespace to which the service is to be deployed according to the namespace identifier recorded in the deployment description file, and obtaining the namespace to be deployed; obtaining the tag of the namespace to be deployed; obtaining a second preset tag, and matching the tag of the namespace to be deployed with the second preset tag to obtain a second matching result; when it is determined according to the second matching result that the tag of the namespace to be deployed has a second matching tag that matches the second preset tag, obtaining the value of the second matching tag; when the value of the second matching tag is the preset target value, determining that the service meets the function providing platform agent access conditions.
[0106] Specifically, in addition to the whitelist mode, the present application also has a blacklist mode. In the blacklist mode, after obtaining the deployment description file, the service deployment platform can determine the namespace to which the service with the deployment description file is to be deployed according to the namespace identifier of the namespace recorded in the deployment description file. For example, the namespace with the namespace identifier recorded in the deployment description file is used as the namespace to which the service is to be deployed. For the convenience of description, the namespace to which the service is to be deployed is referred to as the namespace to be deployed. Among them, the namespace is a declarative area that provides a scope for its internal identifiers (names of types, functions, variables, etc.) to limit the resolution and use scope of the name.
[0107] Further, the service deployment platform may obtain the label of the namespace to be deployed, and obtain the second preset label, and match the label of the namespace to be deployed with the second preset label to determine whether there is a label matching the second preset label in the label of the namespace to be deployed. For the convenience of description, the label that matches the second preset label determined in the blacklist mode is referred to as the second matching label. For example, a label that is the same as or similar to the second matching label may be referred to as the second matching label.
[0108] Further, when the tag of the namespace to be deployed has a second matching tag, the service deployment platform may obtain the value of the second matching tag, and when the value of the second matching tag is the target value, determine that the service meets the function providing platform agent access condition.
[0109] The second preset label may be the same as the first preset label, or may be different from the first preset label.
[0110] In one embodiment, reference Fig.10 , you can add a tag "tsf.tenxxxcloud.com / inject" to namespace A. It is easy to understand that the tag written is a tag that is consistent with the first preset tag. After setting the tag "tsf.tenxxxcloud.com / inject" for namespace A, you can also set the value of the tag to the target value, for example, set it to "enable", so that when the namespace identifier recorded in the deployment description file of service A is the identifier of namespace A, it can be considered that service A meets the function provision platform agent access conditions. It is easy to understand that if multiple services need to be deployed to namespace A, it can be determined in batches that multiple services meet the function provision platform agent access conditions. Fig.10 A schematic diagram of a label in blacklist mode in an embodiment is shown. It is easy to understand that when there is no second matching label in the label of namespace A, or the value of the second matching label is not the target value, for example, when the value of the label "tsf.tenxxxcloud.com / inject" is "disable", it is determined that the service to be deployed to namespace A does not meet the function providing platform proxy access conditions. At this time, the service deployment platform directly deploys the service to be deployed to namespace A based on the deployment description file.
[0111] In one embodiment, an interface server in the service deployment platform may be used to check whether there is a second matching tag in the tag of the namespace to be deployed and whether the value of the second matching tag is a target value.
[0112] In the above embodiment, by adding a tag in the namespace, it is possible to batch determine whether multiple services need to access the function providing platform agent based on the tag, thereby eliminating the need to add corresponding tags one by one in the deployment description file of each service, thereby improving the efficiency of determining whether a service needs to access the function providing platform agent.
[0113] In one of the embodiments, a main node of a service deployment platform includes a platform operation component and an interface server, and the interface server has an access control callback function; when it is determined according to a deployment description file that the service meets the proxy access conditions of the function-providing platform, a proxy access request is generated according to the deployment description file, including: when it is determined that the service meets the proxy access conditions of the function-providing platform, an initial proxy access request carrying the deployment description file is generated through the interface server and based on the access control callback function, and the initial proxy access request is sent to the platform operation component; a proxy access request is generated through the platform operation component and based on the initial proxy access request and a preset digital certificate.
[0114] Specifically, after initialization, and after determining that a platform agent needs to be provided for the service access function according to the tag, the interface server in the service deployment platform can run the access control callback function to generate an initial agent access request through the access control callback function implemented by the access control callback function, and send the initial agent access request to the platform operation component. When the platform operation component receives the initial agent access request, the platform operation component can generate an agent access request based on the initial agent access request and a preset digital certificate. For example, the platform operation component can respond to the initial agent access request, obtain the digital certificate issued by the function provision platform during the initialization process, and generate an agent access request based on the digital certificate.
[0115] In one embodiment, when it is determined that the service meets the platform proxy access conditions for providing functions, the interface server will request the target interface of the platform operation component, for example, the / api / inject interface, so as to trigger the platform operation component to start the new deployment description file generation action by requesting the target interface of the platform operation component. The request for the target interface of the platform operation component can be called an initial proxy access request.
[0116] In one of the embodiments, the function providing platform includes a request relay service and a resource management service; the proxy access request sent is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file, including: the proxy access request sent is used to trigger the request relay service to authenticate the platform operation component based on the digital certificate, and send the proxy access request to the resource management service after the verification is passed, so that the resource management service responds to the proxy access request, adds the configuration information required for deploying the function providing platform agent in the deployment description file, and obtains a new deployment description file.
[0117] Specifically, the platform operation component in the service deployment platform may send the proxy access request to the request relay service of the function provision platform. When the request relay service receives the proxy access request, the request relay service may authenticate the platform operation component based on the digital certificate carried in the proxy access request, and after the authentication is passed, send the proxy access request to the resource management service, so that the resource management service responds to the proxy access request, writes the configuration information required for deploying the function provision platform agent in the deployment description file, and obtains a new deployment description file.
[0118] In the above embodiment, after the identity authentication is passed, the action of generating a new deployment description file is executed, which can improve the security of generating the new deployment description file.
[0119] In one of the embodiments, the main node of the service deployment platform includes a platform operation component; sending a proxy access request to a function provision platform includes: identifying an operation type corresponding to the proxy access request through the platform operation component; the operation type is a type that characterizes an operation on a deployment description file; when the operation type corresponding to the proxy access request is a target operation type, sending the proxy access request to the function provision platform through the platform operation component.
[0120] Specifically, when the platform operation component receives the proxy access request, the platform operation component may identify the operation type corresponding to the proxy access request, which may be a type that characterizes the operation of the deployment description file, for example, the operation type may specifically be a type of addition, deletion, modification, and query. In the case where the type corresponding to the proxy access request is the target operation type, the platform operation component sends the proxy access request to the function providing platform. For example, the target operation type may be an addition type, so when it is determined that the operation type corresponding to the proxy access request is an addition type, the proxy access request is sent to the function providing platform.
[0121] In one embodiment, when the platform operation component generates the proxy access request, it may send the proxy access request to the function providing platform in an encrypted manner. For example, the platform operation component sends the proxy access request to the function providing platform via HTTPS (Hypertext Transfer Protocol Secure).
[0122] In the above embodiment, by sending the proxy access request to the function providing platform after determining that the operation type is the target operation type, the sending security of the proxy access request can be improved.
[0123] In one of the embodiments, the function providing platform includes a resource management service; the agent access request sent is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file, including: the agent access request sent is used to trigger the resource management service to obtain the address of the image of the function providing platform agent and the environment variables required for deploying the function providing platform agent, and add the address and environment variables to the deployment description file to obtain a new deployment description file.
[0124] In this embodiment, by adding the address of the image of the function providing platform agent and the environment variables required for deploying the function providing platform agent to the deployment description file, the function providing platform agent can be deployed based on the added information later.
[0125] In one embodiment, reference Fig.11 , Fig.11 A deployment interaction diagram in an embodiment is shown. The deployment process of the service and function providing platform agent involves an interface server, a platform operation component, a request forwarding service and a resource management service. After the user executes the deployment instruction on the service deployment platform, the preset access control callback function will be triggered in the deployment process of the service deployment platform. This access control callback function will request the / api / inject interface of the platform operation component to start the injection action of the deployment description file. After the platform operation component receives the proxy access request, it will perform preliminary request sorting to determine whether the operation type corresponding to the proxy access request is the target operation type. If it is the target operation type, the proxy access request is sent to the request forwarding service in an encrypted manner. After the request forwarding service receives the proxy access request, it will authenticate the identity of the platform operation component for the request. When the authentication is successful, it will send the proxy access request to the resource management service. The resource management service will identify the action of the proxy access request. If it is a deployment description file editing action, it will start to add the corresponding configuration information in the deployment description file to obtain a new deployment description file. After the new deployment description file is generated, the new deployment description file is returned to the interface server. Finally, after the interface server receives the new deployment description file, it starts to execute the deployment.
[0126] In this application, for users of the service deployment platform, the original deployment habits remain basically unchanged, and the function provision platform can be accessed in the service deployment platform without any perception, allowing users to complete the function provision platform access with basically no burden.
[0127] In one of the embodiments, the deployed function provides a platform agent for interacting with the function providing platform to provide additional functions different from the native functions provided by the service deployment platform for the service; the additional functions include at least one of managing the life cycle of the deployed service, performing service governance on the deployed service, or observing the deployed service.
[0128] Specifically, when executing deployed services, the function providing platform agent can be responsible for the lifecycle management of the services, determine the execution status of the services through the health check mechanism, and restart the service process if the operation is abnormal, and synchronize the execution status to the function providing platform. In addition, the function providing platform agent can also be used to govern the deployed services. Service governance can solve the following problems, such as service discovery (how to find services), load balancing (how to handle the load of services), and security (how to protect services from unauthorized access or attacks), etc. Furthermore, the function providing platform agent can also be used to observe the deployed services. For example, the function providing platform agent can collect the operation information of the service, generate an operation log, and send the operation log to the function providing platform for viewing.
[0129] In this embodiment, by executing the deployment process, the service can be included in the management scope of the function provision platform, so that the function provision platform can provide the service with additional functions out of the box without the user having to edit code on the service deployment platform to implement the additional functions, thereby improving the efficiency of using the additional functions.
[0130] In one specific embodiment, reference Fig.12 , provides a service deployment method, including:
[0131] Step 1202: The interface server of the service deployment platform obtains a deployment description file of the service. The deployment description file records configuration information required for deploying the service.
[0132] Step 1204: The interface server of the service deployment platform obtains a first preset tag, and matches the tag recorded in the deployment description file with the first preset tag to obtain a first matching result.
[0133] Step 1206, when it is determined according to the first matching result that the recorded tags contain a first matching tag that matches the first preset tag, the interface server of the service deployment platform obtains the value of the first matching tag; when the value of the first matching tag is the preset target value, it is determined that the service meets the function providing platform agent access conditions.
[0134] Step 1208, when it is determined based on the first matching result that the recorded tags do not contain a first matching tag that matches the first preset tag, the interface server of the service deployment platform determines the namespace to which the service is to be deployed based on the namespace identifier recorded in the deployment description file, and obtains the namespace to be deployed.
[0135] Step 1210: The interface server of the service deployment platform obtains a label of the namespace to be deployed; obtains a second preset label, and matches the label of the namespace to be deployed with the second preset label to obtain a second matching result.
[0136] Step 1212, when it is determined based on the second matching result that the tag of the namespace to be deployed has a second matching tag that matches the second preset tag, the interface server of the service deployment platform obtains the value of the second matching tag; when the value of the second matching tag is the preset target value, it is determined that the service meets the function providing platform agent access conditions.
[0137] Step 1214, when it is determined according to the deployment description file that the service meets the proxy access conditions of the function providing platform, an initial proxy access request carrying the deployment description file is generated through the interface server of the service deployment platform and based on the access control callback function, and the initial proxy access request is sent to the platform operation component.
[0138] Step 1216, the platform operation component of the service deployment platform generates a proxy access request based on the initial proxy access request and the preset digital certificate, identifies the operation type corresponding to the proxy access request, and when the operation type corresponding to the proxy access request is the target operation type, sends the proxy access request to the request forwarding service of the function provision platform through the platform operation component.
[0139] Step 1218, the function provides the request relay service of the platform, and authenticates the platform operation component based on the digital certificate carried in the proxy access request, and sends the proxy access request to the resource management service of the function providing platform after the authentication is passed.
[0140] Step 1220, the resource management service of the function providing platform responds to the agent access request, obtains the address of the image of the function providing platform agent and the environment variables required to deploy the function providing platform agent, adds the address and environment variables to the deployment description file, obtains the new deployment description file, and returns the new deployment description file to the service deployment platform.
[0141] Step 1222, the interface server of the service deployment platform triggers the deployment of services and function providing platform agents in the slave nodes of the service deployment platform based on the new deployment description file returned by the function providing platform; the deployed function providing platform agent is used to interact with the function providing platform to provide additional functions that are different from the native functions provided by the service deployment platform for the service.
[0142] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0143] The present application also provides an application scenario, which applies the above service deployment method. Specifically, the application of the service deployment method in the application scenario is as follows:
[0144] refer to Fig.13 , Fig.13The overall framework diagram of service deployment in one embodiment is shown. When the administrator of the function providing platform (for example, microservice platform) can perform initialization operation in the console, there are two ways to complete the initialization. One is to execute the first initialization process: the user's initialization operation, after being parsed by the resource management service (also known as tsf-resource), directly sends the first initialization request to the service deployment platform (also known as K8s platform) through cluster management. At this time, after the service deployment platform (also known as K8s platform) receives the first initialization request, it will create a platform operation component (also known as tsf-operator component), and add an access control callback function (also known as admission webhook) in the interface server (also known as api-server). Another initialization method is to execute the second initialization process: when the user chooses manual initialization, the user will directly receive the creation of the required initialization file (also known as yaml file) provided by the resource management service (also known as tsf-resource). At this time, the user can submit the initialization file to the administrator of the service deployment platform, and then the administrator with platform write permission will import the initialization file into the service deployment platform, so that the service deployment platform can be initialized through the initialization file. When the platform operation component runs in the control plane component of the service deployment platform, the initialization task is completed.
[0145] Next, users can directly deploy services on the service deployment platform. Fig.13 As shown. When the deployment description file (also called Deployement) deployed by the user meets the injection conditions, the access control callback function deployed in the interface server will be triggered to send the deployment description file of this deployment to the platform operation component. After receiving the deployment description file, the platform operation component identifies the operation type and then sends the deployment file to the request transfer service (also called tsf-kube service) on the function provision platform side. The request transfer service will first verify the identity of the platform operation component. After the identity authentication is passed, the resource management service will complete the injection of the deployment description file to add the configuration information required for the deployment function provision platform agent to the deployment description file to obtain a new deployment description file. The new deployment description file is then returned to the request transfer service, which sends the new deployment description file to the interface server through the request transfer service. When the interface server receives the new deployment description file, the deployment process of the service deployment platform begins. The above series of actions can be called function provision platform agent injection. A service that has completed the function provision platform agent injection is shown as follows. Fig.13 As shown, a module providing a platform agent function is added to the slave node where the service is located.
[0146] At this point, by default, all deployed services belong to the whitelist mode. In this mode, the function provider platform agent injection will be triggered only when the deployment description file contains the tag specified by the function provider platform: tsf.tenxxxcloud.com / inject, and the value is the target value, such as enable. If the user finds it cumbersome to add tags to each service, you can also directly add the tag specified by the function provider platform in the namespace: tsf.tenxxxcloud.com / inject, and set it to enable. At this time, the services deployed to this namespace will trigger the injection of the function provider platform agent. For the services in this namespace, if you do not want to inject the function provider platform agent, set the tsf.tenxxxcloud.com / inject t tag of the namespace to disable. Because this method requires explicit rejection of proxy injection, it is called blacklist mode.
[0147] It is worth noting that the above method can be used to deploy services for both incremental services and existing services in the service deployment platform.
[0148] The specific beneficial effects of this application include:
[0149] The complexity of accessing the function provision platform is simplified for users. In the traditional fully managed mode of the function provision platform, users need to follow the guidance of the function provision platform to complete the access step by step, and deploy services on the function provision platform after access. When users switch from the service deployment platform to the function provision platform, it also brings new learning costs and needs to change the original operating habits. In this application, for users of the service deployment platform, there is no need to make major adjustments to the original operations. Simply setting labels can achieve access to the function provision platform, which greatly simplifies the complexity of access. In addition, after accessing the function provision platform, you can also easily obtain additional functions provided by the function provision platform.
[0150] It is convenient for old users to migrate and avoid the problem of duplicate construction. There are many old users on the function provision platform. As the business scenarios become more and more complex, the original command-based deployment method that relies on the console has become repetitive and cumbersome. Users hope to have service orchestration capabilities in the application dimension to complete large-scale deployment. However, these demands are complex to implement on the function provision platform, and there is a problem of duplicate construction of capabilities. With the deployment method of this application, users can use a cloud-native approach to deploy all services in the service deployment platform, and realize the service orchestration capabilities in the application dimension through the native functions of the service deployment platform to complete large-scale deployment. Since the service orchestration capabilities in the application dimension can be realized through the native functions of the service deployment platform to complete large-scale deployment, users of the function provision platform are exempted from secondary development of the function provision platform to realize service orchestration capabilities and complete large-scale deployment capabilities, thereby avoiding the problem of duplicate construction.
[0151] High degree of freedom in service deployment. Since services can be deployed in the service deployment platform in a cloud-native way, the degree of freedom in service deployment is greatly improved compared to deploying services through a function provision platform.
[0152] Split service operation and maintenance and service governance. When the business scale of the users of the function provision platform grows, the users will want to split the operation and maintenance team and the business team. For example, the life cycle management of the application will be handed over to a dedicated operation and maintenance team. The business team only needs to be responsible for its own business. However, this demand cannot be met on the original function provision platform, because all deployment processes and service governance capabilities rely on the function provision platform. Therefore, for users, all operations of the operation and maintenance and business teams are concentrated in a unified view. In this application, the operation and maintenance team can use the service deployment platform to deploy services, and the business team can use the function provision platform for business processing, thereby realizing the split of the operation and maintenance team and the business team.
[0153] Circumventing permission restrictions. In larger-scale customer usage requirements, the service deployment platform and the function provision platform belong to completely different teams, and all user operations are subject to strict permission control. The business team does not have full permissions to the service deployment platform, only basic read permissions. In this scenario, if business users want to use the function provision platform, the traditional function provision platform will encounter obstacles in controlling the instruction flow of the service deployment platform, because the service deployment platform cannot be imported into the function provision platform at all, and the function provision platform cannot operate the components of the service deployment platform. This application will actively trigger the operation of the function provision platform when the service deployment platform is deployed, so as to circumvent the isolation and permission restrictions of the service deployment platform and the function provision platform.
[0154] The present application also provides an application scenario, which applies the above-mentioned service deployment method.
[0155] Specifically, the application of the service deployment method in this application scenario is as follows:
[0156] When it is necessary to deploy a service for implementing image detection, the service deployment platform can obtain a new deployment description file for the service in the above manner, and deploy the service to a pod through the new deployment description file, and deploy a function providing platform agent for the service in the pod, so that when the service is run, the input image can be detected through the service, and management functions can be provided for the service through the function providing platform agent.
[0157] The above application scenarios are only for illustrative purposes. It should be understood that the application of the service deployment method provided in each embodiment of the present application is not limited to the above scenarios.
[0158] Based on the same inventive concept, the embodiment of the present application also provides a service deployment device for implementing the service deployment method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more service deployment device embodiments provided below can refer to the limitations on the service deployment method above, and will not be repeated here.
[0159] In one embodiment, Fig.14 As shown, a service deployment device 1400 is provided, including: a request generation module 1402, a new file generation module 1404 and a deployment implementation module 1406, wherein:
[0160] The request generation module 1402 is used to obtain the deployment description file of the service, which records the configuration information required for deploying the service; when it is determined according to the deployment description file that the service meets the agent access conditions of the function providing platform, an agent access request is generated according to the deployment description file.
[0161] The new file generation module 1404 is used to send an agent access request to the function providing platform. The sent agent access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file.
[0162] The deployment implementation module 1406 is used to trigger the deployment of services and function providing platform agents in the slave nodes of the service deployment platform based on the new deployment description file returned by the function providing platform.
[0163] In one embodiment, the service deployment device 1400 also includes an initialization module, which is used to receive an initialization request issued by a function providing platform; in response to the initialization request, a platform operation component is created and an access control callback function is added; the platform operation component is used to transmit requests between the function providing platform; the access control callback function is implemented through an access control callback function, which is a function used to implement custom control logic in the process of generating a new deployment description file.
[0164] In one of the embodiments, the initialization request sent by the function providing platform is a request generated by a resource management service in the function providing platform in response to an initialization type selection operation, and based on the initialization type selection operation, when determining to execute the first initialization process, a request is generated according to the meta-information of the function providing platform.
[0165] In one of the embodiments, the initialization module is also used to receive an initialization request sent by a request forwarding service of a function providing platform through an interface server in a master node of the service deployment platform; wherein the interface server is a server for receiving and processing requests and for managing resource objects in slave nodes of the service deployment platform; the request forwarding service is a service that communicates with a resource management service in the function providing platform and receives an initialization request generated by the resource management service.
[0166] In one of the embodiments, the initialization module is also used to obtain the image of the access control callback function and the platform operation component in response to the initialization request; add a new platform operation component through the image of the platform operation component, and add the access control callback function in the interface server in the main node of the service deployment platform through the access control callback function.
[0167] In one of the embodiments, the service deployment device 1400 further includes an initialization module for receiving an initialization file provided by a function providing platform; creating a platform operation component and adding an access control callback function through the initialization file.
[0168] In one of the embodiments, the initialization file is input into the service deployment platform by the administrator of the service deployment platform; the initialization file obtained by the administrator of the service deployment platform is a file that responds to the initialization type selection operation through the resource management service in the function provision platform, and triggers the request transfer service feedback in the function provision platform when it is determined to execute the second initialization process based on the initialization type selection operation.
[0169] In one of the embodiments, the request generation module 1402 is also used to obtain a first preset tag, and match the tag recorded in the deployment description file with the first preset tag to obtain a first matching result; when it is determined according to the first matching result that the recorded tag contains a first matching tag that matches the first preset tag, the value of the first matching tag is obtained; when the value of the first matching tag is the preset target value, it is determined that the service meets the function providing platform agent access conditions.
[0170] In one of the embodiments, the request generation module 1402 is also used to determine the namespace to which the service is to be deployed based on the namespace identifier recorded in the deployment description file, and obtain the namespace to be deployed; obtain the label of the namespace to be deployed; obtain a second preset label, and match the label of the namespace to be deployed with the second preset label to obtain a second matching result; when it is determined based on the second matching result that the label of the namespace to be deployed has a second matching label that matches the second preset label, obtain the value of the second matching label; when the value of the second matching label is the preset target value, it is determined that the service meets the function providing platform agent access conditions.
[0171] In one of the embodiments, the main node of the service deployment platform includes a platform operation component and an interface server, and the interface server has an access control callback function; the request generation module 1402 is also used to generate an initial proxy access request carrying a deployment description file through the interface server and based on the access control callback function when it is determined that the service meets the function of providing platform proxy access conditions, and send the initial proxy access request to the platform operation component; through the platform operation component, a proxy access request is generated based on the initial proxy access request and a preset digital certificate.
[0172] In one of the embodiments, the function providing platform includes a request relay service and a resource management service; the proxy access request sent is used to trigger the request relay service to authenticate the platform operation component based on the digital certificate carried in the proxy access request, and send the proxy access request to the resource management service after the verification is passed, so that the resource management service responds to the proxy access request, adds the configuration information required for deploying the function providing platform agent in the deployment description file, and obtains a new deployment description file.
[0173] In one of the embodiments, the new file generation module 1404 is also used to identify the operation type corresponding to the proxy access request through the platform operation component; the operation type is a type that characterizes the operation on the deployment description file; when the operation type corresponding to the proxy access request is the target operation type, the proxy access request is sent to the function provision platform through the platform operation component.
[0174] In one of the embodiments, the function providing platform includes a resource management service; the proxy access request sent is used to trigger the resource management service to obtain the address of the image of the function providing platform agent and the environment variables required to deploy the function providing platform agent, and add the address and environment variables to the deployment description file to obtain a new deployment description file.
[0175] In one of the embodiments, the additional functions include at least one of managing the lifecycle of the deployed services, performing service governance on the deployed services, or observing the deployed services.
[0176] Each module in the above service deployment device can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module above.
[0177] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Fig.15 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store service deployment data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a service deployment method is implemented.
[0178] Those skilled in the art will understand that Fig.15 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0179] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.
[0180] In one embodiment, a computer-readable storage medium is provided, storing a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0181] In one embodiment, a computer program product or computer program is provided, the computer program product or computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the steps in the above-mentioned method embodiments.
[0182] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0183] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0184] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0185] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be construed as limiting the scope of the present application. It should be noted that, for a person of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A service deployment method, characterized in that: Applied to a master node of a service deployment platform, the method comprises: Obtaining a deployment description file of a service, wherein the deployment description file records configuration information required to deploy the service; In the case where it is determined according to the deployment description file that the service meets the proxy access condition of the function providing platform, generating a proxy access request according to the deployment description file; Sending the proxy access request to the function providing platform, wherein the sent proxy access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file; Based on the new deployment description file returned by the function providing platform, the deployment of the service and the function providing platform agent in the slave node of the service deployment platform is triggered.
2. The method according to claim 1, characterized in that The method further comprises: Receiving an initialization request sent by the function providing platform; In response to the initialization request, a platform operation component is created and an access control callback function is added; the platform operation component is used to transparently transmit requests with the function providing platform; the access control callback function is implemented through an access control callback function, and the access control callback function is a function used to implement custom control logic in the process of generating a new deployment description file.
3. The method according to claim 2, characterized in that The initialization request sent by the function providing platform is a request generated by the resource management service in the function providing platform in response to the initialization type selection operation and based on the metadata of the function providing platform when determining to execute the first initialization process based on the initialization type selection operation.
4. The method according to claim 2, characterized in that: The receiving the initialization request sent by the function providing platform includes: Receiving, through an interface server in a master node of the service deployment platform, an initialization request sent by a request forwarding service of the function provision platform; Wherein, the interface server is a server for receiving and processing requests and for managing resource objects in the slave nodes of the service deployment platform; The request forwarding service is a service that communicates with the resource management service in the function providing platform and receives an initialization request generated by the resource management service.
5. The method according to claim 2, characterized in that: The creating function provides a platform operation component and adds an access control callback function in response to the initialization request, including: In response to the initialization request, obtaining an image of an access control callback function and a platform operation component; A new platform operation component is added through the mirroring of the platform operation component, and an access control callback function is added to the interface server in the main node of the service deployment platform through the access control callback function.
6. The method according to claim 1, characterized in that The method further comprises: Receiving an initialization file provided by the function providing platform; Through the initialization file, a platform operation component is created and an access control callback function is added.
7. The method according to claim 6, characterized in that The initialization file is input into the service deployment platform by the administrator of the service deployment platform; the initialization file obtained by the administrator of the service deployment platform is a file that triggers the request transit service feedback in the function providing platform when the resource management service in the function providing platform responds to the initialization type selection operation and determines to execute the second initialization process based on the initialization type selection operation.
8. The method according to claim 1, characterized in that The step of determining whether the service meets the access conditions of the function providing platform agent according to the deployment description file comprises: Obtaining a first preset tag, and matching the tag recorded in the deployment description file with the first preset tag to obtain a first matching result; When it is determined according to the first matching result that the recorded tags have a first matching tag that matches the first preset tag, obtaining a value of the first matching tag; When the value of the first matching tag is a preset target value, it is determined that the service meets the function providing platform agent access condition.
9. The method according to claim 1, characterized in that: The method further comprises: Determine the namespace to which the service is to be deployed according to the namespace identifier recorded in the deployment description file, and obtain the namespace to be deployed; Obtain a label for the namespace to be deployed; Obtaining a second preset tag, and matching the tag of the namespace to be deployed with the second preset tag to obtain a second matching result; When it is determined according to the second matching result that the label of the namespace to be deployed has a second matching label that matches the second preset label, obtaining a value of the second matching label; When the value of the second matching tag is a preset target value, it is determined that the service meets the function providing platform agent access condition.
10. The method according to claim 1, characterized in that The main node of the service deployment platform includes a platform operation component and an interface server, and the interface server has an access control callback function; The step of generating a proxy access request according to the deployment description file, when it is determined according to the deployment description file that the service meets the proxy access condition of the function providing platform, comprises: In the case of determining that the service meets the proxy access condition of the function providing platform, generating an initial proxy access request carrying the deployment description file through the interface server and based on the access control callback function, and sending the initial proxy access request to the platform operation component; An agent access request is generated through the platform operating component according to the initial agent access request and a preset digital certificate.
11. The method according to claim 10, characterized in that The function providing platform includes a request forwarding service and a resource management service; the sent agent access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent, and obtain a new deployment description file, including: The proxy access request sent is used to trigger the request relay service to authenticate the platform operation component based on the digital certificate carried in the proxy access request, and send the proxy access request to the resource management service after the verification is passed, so that the resource management service responds to the proxy access request, adds a deployment function in the deployment description file to provide the configuration information required by the platform agent, and obtains a new deployment description file.
12. The method according to claim 1, characterized in that The master node of the service deployment platform includes a platform operation component; the sending of the proxy access request to the function provision platform includes: Identifying, by means of the platform operation component, an operation type corresponding to the proxy access request; the operation type is a type that characterizes an operation performed on the deployment description file; In a case where the operation type corresponding to the proxy access request is a target operation type, the proxy access request is sent to a function providing platform through the platform operation component.
13. The method according to claim 1, characterized in that The function providing platform includes a resource management service; the sent agent access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent to obtain a new deployment description file, including: The proxy access request sent is used to trigger the resource management service to obtain the address of the mirror of the platform proxy and the environment variables required by the deployment function to provide the platform proxy, and add the address and the environment variables to the deployment description file to obtain a new deployment description file.
14. The method according to any one of claims 1 to 13, characterized in that: a deployed function providing platform agent for interacting with the function providing platform to provide additional functions different from the native functions provided by the service deployment platform for the service; The additional functions include at least one of managing the lifecycle of the deployed service, performing service governance on the deployed service, or observing the deployed service.
15. A service deployment device, characterized in that: The device comprises: A request generation module, configured to obtain a deployment description file of a service, wherein the deployment description file records configuration information required for deploying the service; and when it is determined according to the deployment description file that the service meets the proxy access conditions of the function providing platform, generate a proxy access request according to the deployment description file; A new file generation module, used to send the proxy access request to the function providing platform, wherein the sent proxy access request is used to instruct the function providing platform to update the deployment description file according to the configuration information required for deploying the function providing platform agent, so as to obtain a new deployment description file; The deployment implementation module is used to trigger the deployment of the service and the function providing platform agent in the slave node of the service deployment platform based on the new deployment description file returned by the function providing platform.
16. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 14 are implemented.
17. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are implemented.
18. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are implemented.