Container management method and device and storage medium

By dynamically analyzing and predicting the characteristics and resource requirements of container tasks, and adjusting the resource allocation and permission settings of containers in real time, solving the unreasonable resource allocation and security risks caused by static management strategies in the existing technology, and achieving more efficient and secure container management.

CN120010994APending Publication Date: 2025-05-16BEIJING THUNDERSTONE TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510081210.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing container management methods rely on static resources and permission management strategies, lack dynamic adaptability, resulting in unreasonable resource allocation and inflexible permission control, and security risks.

Method used

By analyzing task characteristics when starting target tasks, predicting the best configuration parameters, dynamically adjusting the resource allocation and permission settings of the container, and responding to task demand changes and abnormal behavior in a timely manner.

Benefits of technology

Optimize container resource allocation, reduce operating costs, improve system security, and ensure the rational allocation and use of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010994A_ABST
    Figure CN120010994A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of containerization, and provides a container management method which comprises the steps that when a target task is started, the target task is analyzed to obtain task characteristics of the target task; on the basis of historical data and task characteristics of the target task, predicting optimal configuration parameters of the target container; according to the optimal configuration parameters of the target container, creating the target container and allocating resources to the target container; setting the permission of the target container according to the task characteristics of the target task; when demand changes or abnormal behaviors occur in the process of executing the target task according to the optimal configuration parameters of the target container, the permission set for the target container and the allocated resources are dynamically adjusted; after the target task is completed, the target container is destroyed, and the container management strategy is adjusted according to feedback of the large model. According to the technical scheme, the resource allocation of the container can be optimized, the operation cost is reduced, and the safety of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of containerization, and in particular to a container management method, device and storage medium. Background Art

[0002] With the rapid development of container technology, more and more applications are using containerized deployment to improve resource utilization, flexibility, and scalability. In a multi-tenant environment, containers act as resource isolation units and provide independent execution environments for different tasks and services. However, the problems involved in container management have gradually revealed security risks. How to effectively prevent malicious tasks from abusing permissions and ensure the security of the system has become a technical problem that needs to be solved urgently.

[0003] Existing container management methods mostly rely on static management strategies for resources and permissions, that is, each container task accesses resources according to preset roles and permissions. This container management method has major limitations, including lack of dynamic adaptability, fixed resource allocation, and permission abuse and unauthorized access, etc. In short, existing technologies cannot fully guarantee the rationality of resource allocation, flexibility of permission control, and security in containerized environments. Summary of the invention

[0004] The present application provides a container management method, device and storage medium, which can optimize the resource allocation of containers, reduce operating costs and improve the security of the system.

[0005] In one aspect, the present application provides a container management method, the method comprising:

[0006] When starting a target task, analyzing the target task to obtain the task characteristics of the target task;

[0007] Predicting optimal configuration parameters of the target container based on historical data and task characteristics of the target task;

[0008] According to the optimal configuration parameters, create the target container and allocate resources to the target container;

[0009] According to the task characteristics of the target task, setting the permissions of the target container;

[0010] When demand changes or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters, dynamically adjust the permissions set for the target container and the allocated resources;

[0011] After the target task is completed, the target container is destroyed and the container management strategy is adjusted according to the feedback of the large model.

[0012] In another aspect, the present application provides a container management device, the device comprising:

[0013] An analysis module, used for analyzing the target task to obtain the task characteristics of the target task when starting the target task;

[0014] A prediction module, used for predicting optimal configuration parameters of a target container based on historical data and task characteristics of the target task;

[0015] A creation module, used for creating the target container and allocating resources to the target container according to the optimal configuration parameters;

[0016] A setting module, used to set the permissions of the target container according to the task characteristics of the target task;

[0017] An adjustment module, configured to dynamically adjust permissions set for the target container and allocated resources when demand changes or abnormal behaviors occur during the execution of the target task according to the optimal configuration parameters;

[0018] The destruction module is used to destroy the target container after the target task is completed and adjust the container management strategy according to the feedback of the large model.

[0019] In a third aspect, the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the technical solution of the above-mentioned container management method when executing the computer program.

[0020] In a fourth aspect, the present application provides a storage medium storing a computer program, which, when executed by a processor, implements the steps of the technical solution of the above-mentioned container management method.

[0021] From the technical solution provided by the present application, it can be seen that after predicting the optimal configuration parameters of the target container, creating the target container and allocating resources to the target container according to the optimal configuration parameters, when demand changes or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters, the permissions set for the target container and the allocated resources are dynamically adjusted. On the one hand, by predicting the required resource configuration according to the characteristics of the target task, the resource allocation of the container can be optimized; on the other hand, by dynamically adjusting the allocated resources, it can not only ensure that the target container always has sufficient computing, storage, network and other resources during operation, thereby maintaining a high performance level, but also reduce unnecessary resource expenditures and reduce operating costs; thirdly, dynamically adjusting the permissions set for the target container can not only adjust the permissions in real time according to the actual task behavior to ensure the reasonable allocation and use of resources, but also effectively prevent the task from abusing permissions or unauthorized access, thereby improving the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0023] Figure 1 is a flow chart of a container management method provided by an embodiment of the present application;

[0024] Figure 2 is a schematic diagram of the structure of a container management device provided in an embodiment of the present application;

[0025] Figure 3 It is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0027] In this specification, adjectives such as first and second may be used only to distinguish one element or action from another element or action, without necessarily requiring or implying any actual such relationship or order. Where circumstances permit, reference to an element or component or step (etc.) should not be interpreted as being limited to only one of the elements, components, or steps, but may be one or more of the elements, components, or steps, etc.

[0028] In this specification, for the convenience of description, the sizes of various parts shown in the drawings are not drawn according to the actual proportional relationship.

[0029] Existing container management methods mostly rely on static management strategies for resources and permissions, that is, each container task accesses resources based on preset roles and permissions. This container management method has significant limitations, as described below:

[0030] 1) Lack of dynamic adaptability. That is, existing technologies are often unable to dynamically adjust container permissions according to real-time changes in task behaviors. Changes in permissions are more dependent on manual or fixed rules, and are unable to respond to abnormal behaviors in a timely manner.

[0031] 2) Unable to monitor abnormal behavior in real time. That is, many container management systems cannot monitor the specific behavior of tasks in the container in real time, resulting in the inability to identify and take effective measures in time when abnormal behavior occurs in tasks;

[0032] 3) Abuse of permissions and unauthorized access. That is, during the execution of some complex tasks, malicious tasks may exploit permission loopholes or permission configuration errors to gain unauthorized access, thereby affecting the security of the entire system.

[0033] In short, existing technologies cannot fully guarantee the flexibility and security of permission control in containerized environments. In particular, there are still large technical gaps and room for improvement in terms of dynamic adjustment of permissions and monitoring of abnormal behaviors.

[0034] In view of the above problems in the prior art, this application proposes a container management method, the flow chart of which is shown in the attached Figure 1 As shown, it mainly includes steps S101 to S106, which are described in detail as follows:

[0035] Step S101: when starting a target task, analyzing the target task to obtain task characteristics of the target task.

[0036] In an embodiment of the present application, the target task is a task received by the system and needs to be executed in a containerized environment. The task characteristics of the target task include the resource type, execution time, and permission requirements required to execute the target task, etc. Since the task characteristics of the target task are closely related to the resources and permissions required for its execution, when the target task is started, the task characteristics of the target task are analyzed. As an embodiment of the present application, when the target task is started, analyzing the target task to obtain the task characteristics of the target task can be implemented through steps S1011 to S1013, as described in detail as follows:

[0037] Step S1011, based on historical data, analyzing the resource type and execution time required to execute the target task.

[0038] In an embodiment of the present application, historical data includes the execution time and the required resource type when the target task (or a task similar to the target task) is executed in the actual production environment or the simulation environment in history, etc. This means that if the target task is a task that has been executed before, the resource type and execution time required for executing the target task can be analyzed based on historical data, such as the type of target task that has been executed before, the requested resource situation (including CPU, memory size, storage capacity, etc.) and the duration of executing the target task, etc. If the target task is a task that has not been executed before, the historical data of tasks similar to the target task can be referred to to analyze the resource type and execution time required for executing the target task. Of course, if the target task or tasks similar to the target task have never been executed in the actual production environment, then it is also possible to execute the target task or conduct a small-scale trial run in the simulation environment by constructing an environment similar to the actual production environment, observing the execution of the target task, and using the execution data of the target task in the simulation environment (including resource requirements (CPU, memory, storage, etc.), execution time, and container destruction time, etc.) as historical data.

[0039] Step S1012, obtaining the permission requirement of the target task by analyzing the source code and / or dependent library of the target task.

[0040] Since sensitive operations involved in the code will be marked as potential permission requirements. For example: `open()`: may require file read permission, `socket()`: may require network access permission, `exec()`: may require execution permission, and so on. Therefore, all system calls, file operations, network access, external library dependencies and other information in the code are extracted through static code analysis tools (such as Clang, SonarQube), which are usually the main source of permission requirements. Similarly, many applications rely on third-party libraries to implement specific functions. These libraries may introduce additional permission requirements. For example, some libraries (such as database connection libraries, cloud service SDKs, etc.) usually require specific permissions. Therefore, analyzing these dependent libraries can help understand the permission requirements of the entire system and ensure that no unnecessary permissions are requested, thereby reducing security risks. In other words, the permission requirements of the target task are obtained by analyzing the source code and / or dependent libraries of the target task.

[0041] Step S1013, based on the analysis results of the source code and dependent libraries of the target task, a permission requirement set of the target task is generated by establishing a permission mapping table.

[0042] By combining static code analysis and library analysis, a permission mapping table is established to map different operations with corresponding permissions, including the mapping between the operation of opening a file and the permission to read the file, the mapping between the permission to connect through a socket and the network access, and the mapping between execution and execution permissions, etc., namely: `open()->READ_ACCESS` (read file permission), `socket()->NETWORK_ACCESS` (network access permission), `exec()->EXECUTE_ACCESS` (execution permission). Based on the above analysis, a permission requirement report for the task is generated, and the final permission requirement set is output.

[0043] Step S102: predicting optimal configuration parameters of the target container based on historical data and task characteristics of the target task.

[0044] In the embodiment of the present application, the task characteristics and resource requirements of the target task have a certain correlation. This correlation may be a relatively simple linear relationship. For example, the more complex the task, the more resources are required, and vice versa. It may also be a more complex nonlinear relationship. Therefore, the optimal configuration parameters of the target container can be predicted based on the relationship between the task characteristics and resource requirements of the target task. Specifically, based on historical data and the task characteristics of the target task, the prediction of the optimal configuration parameters of the target container can be achieved through steps S1021 and S1022, as described in detail as follows:

[0045] Step S1021: If there is a linear relationship between the task characteristics of the target task and the resource requirements, the optimal configuration parameters of the target container are predicted based on historical data and regression analysis methods.

[0046] Assume that the resource requirements of the target task and the task characteristics are the following linear regression model:

[0047] R task =β0+β1*exce_time+β2*rights+ε

[0048] Among them, R task is the resource requirement of the target task (such as CPU, memory, storage, etc.), exce_time is the execution time of the target task, rights is the permission requirement of the target task, β0, β1 and β2 are regression coefficients, and ε is the error term.

[0049] The least squares method can be used to train the above linear regression model, and by fitting historical data, the above linear regression model under the optimal regression coefficients β0, β1 and β2 can be obtained. Specifically, it is assumed that the linear regression model between the execution data of the target task and the task characteristics is expressed as follows:

[0050] yi =β0+β1x i1 +β2x i2 +...+β n x in +ε i

[0051] In the above linear regression model, y i and x i1 ,x i2 ,...,x in It can be the historical data of the above-mentioned embodiment, where y i It is the historical execution data of target task i in the actual production environment or simulation environment, which can be the resource requirements (CPU, memory, storage, etc.) when the target task is executed or the container destruction time, etc. i1 ,x i2 ,...,x in is the task characteristics of target task i, including the historical execution time, data size, required resource types, and permission requirements of the target task, etc., β0,β1,β2,...,β n is the parameter of the regression model, which indicates the influence weight of different task characteristics on the target variable, ε i is the error term, which represents the difference between the model and the actual data. The optimal regression coefficients β0,β1,β2,...,β n , that is, by minimizing the following objective function:

[0052]

[0053] Where m is the number of samples of historical data, It is the predicted value of the model, that is, the predicted resource requirements (CPU, memory, storage, etc.) when the target task is executed, which serves as the optimal configuration parameter of the target container.

[0054] Step S1022: If there is a nonlinear relationship between the task characteristics and resource requirements of the target task, the optimal configuration parameters of the target container are predicted based on historical data and machine learning.

[0055] If there is a nonlinear relationship between the task characteristics and resource requirements of the target task, the above linear regression model cannot predict the optimal configuration parameters of the target container, and a support vector machine, random forest or deep neural network can be used for prediction. In the embodiment of the present application, it is assumed that a random forest model is used to predict the optimal configuration parameters of the target container, and the training data is the historical data of the following target tasks:

[0056] {(features1,R task1 ),(features2,Rtask2 ),...,(features i ,R taski ),...,(features n ,R taskn )}

[0057] Among them, features i is the task characteristics of the i-th target task (including the required resource type, execution time, permission requirements, etc.), R taski For features i The corresponding resource requirements.

[0058] By using the above training data and building multiple decision trees, the random forest model learns the nonlinear relationship between the task characteristics and resource requirements of the target task.

[0059] In the prediction stage, when a new task feature T is given for the target task new =(exce_time new ,rights new ), use the linear regression model obtained by the above fitting or the random forest model obtained by training to predict the resource requirements R of the target task new :

[0060] R new =f(T new )

[0061] Where f() represents the resource requirement R of the target task predicted by the linear regression model obtained by the above fitting or the random forest model obtained by training. new As the optimal configuration parameters for the target container.

[0062] Step S103: creating a target container and allocating resources to the target container according to the optimal configuration parameters of the target container.

[0063] The process of creating a target container is actually the process of creating a container instance. In the embodiment of the present application, the container management platform can be used to create the target container through the following steps:

[0064] 1) Select a container image, that is, select a suitable image from the container image repository. If it is a custom task, you may need to build and upload the image in advance.

[0065] 2) Configure the container startup command, that is, use the predefined configuration file to configure the container startup parameters, including port mapping, environment variables, mounted volumes, etc.;

[0066] 3) Resource allocation, that is, during the creation of the target container, the container management platform controls the CPU, memory, storage and other resources it uses based on the predicted optimal configuration parameters to prevent excessive resource consumption.

[0067] It should be noted that the above-mentioned resource allocation, that is, the container management platform controls the use of CPU, memory, storage and other resources according to the predicted optimal configuration parameters, is the initial allocation of resources or the initialization of resource allocation, which means that the resources may be dynamically adjusted later.

[0068] Step S104: according to the task characteristics of the target task, set the permissions of the target container.

[0069] The so-called container permissions refer to the access control of containers to resources, file systems, networks, hardware devices, etc. in an operating system or virtualization environment, including file system access permissions, network permissions, device access permissions, process and system resource access permissions, and user permissions, etc. Containers may have different permission requirements for performing different tasks. For example, data processing containers may need to access external storage resources (disks, databases), network service containers may need to open ports and provide network access, and machine learning training containers may need to access GPUs and increase computing resources. The same container may have different permissions at different stages of a task. The container reads data from files. At the beginning, the container may only need read-only permissions to read input files. If the task is executed in the middle stage, the container may need write permissions to the file system to save the processing results to local files. In some cases, if the task requires remote communication or scheduling work, the container may need additional network permissions (for example, connecting to a specific API service or database). Since containers have different permission requirements based on different tasks or different stages of the same task, therefore, in the embodiment of the present application, according to the task characteristics of the target task, setting the permissions of the target container can be to set the initial permissions of the target container according to the task characteristics of the target task. Specifically, it can be to set the initial permissions of the target container based on the target task obtained after the aforementioned analysis of the target task and based on the principle of least privilege, the default role of the target container or the type of the target container. The so-called setting the initial permissions of the target container based on the principle of least privilege means that based on the needs of the task, the target container is set to the minimum permissions that can only access the resources it needs when it is created. For example, if the target container only needs to read files in a folder, the target container is only granted the read permission of the folder, and cannot perform write or delete operations; similarly, the target container can only access limited network ports and cannot access other services at will, etc. Setting the initial permissions of the target container based on the default role of the target container means that in some cases, the target container is assigned a predefined role (such as administrator, user, developer, etc.) and permissions are granted according to the role. For example, the target container in the administrator role may have the permissions to create, modify, delete containers, and modify configurations. The target container in the developer role can deploy and debug the container, but cannot modify the system configuration. The target container in the user role can only access its own container or specified resources, and the operation permissions are limited. This method simplifies permission management by setting predefined roles. As for setting the initial permissions of the target container based on the type of the target container, it means assigning different initial permissions according to the functional type of the target container.For example, if the target container is a Web service container, it may only need to access the network and specific static folders. If the target container is a database container, higher permissions are required to access database files and perform query operations. If the target container is a computing task container, it only needs to access computing resources and does not need to perform frequent operations on storage, etc. This method of setting the initial permissions of the target container divides permissions based on the function and purpose of the container, and is suitable for some situations where containerized application scenarios are relatively fixed.

[0070] Step S105: When demand changes or abnormal behaviors occur during the execution of the target task according to the optimal configuration parameters, the permissions set and the allocated resources of the target container are dynamically adjusted.

[0071] As mentioned above, based on different tasks or different stages of the same task, containers have different permission requirements. The initial permissions set at the beginning of the creation of the target container may not be suitable for the actual scenario, so dynamic adjustment is required. Similarly, as the target task is executed, changes in requirements or abnormal situations may occur during the period, which also requires adjustment of the originally allocated resources. Specifically, when changes in requirements or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters, the dynamic adjustment of the permissions set and the allocated resources of the target container can be achieved through steps S1051 and S1052, as described in detail as follows:

[0072] Step S1051: when executing the target task according to the optimal configuration parameters, if the target task execution lags, resource consumption exceeds a threshold, input / output bottlenecks or abnormal behavior occur, then the resource allocation to the target task is adjusted based on the incremental adjustment factor.

[0073] If the execution progress of the target task lags behind expectations, it may be due to insufficient resource allocation or the task complexity is higher than expected, and resources need to be added dynamically. If the resource usage of the target task (especially CPU or memory) increases abnormally, it may indicate that the algorithm of the target task is inefficient or there are problems such as memory leaks. In the case of excessive resource consumption, you can reduce resource allocation to avoid the task occupying too many resources or migrate the target task to other containers by optimizing the algorithm or load balancing. If the target task is inefficient due to slow disk I / O or network transmission speed, you can adjust resources in the following ways: 1) Increase storage bandwidth, that is, by dynamically allocating more disk bandwidth or switching to faster storage devices; 2) Optimize network bandwidth, that is, increase network bandwidth or adjust container network configuration. If an exception occurs during the execution of the target task (such as task crash, memory overflow, etc.), it can automatically roll back to the previous resource configuration or reallocate resources, and trigger the error handling mechanism, including the following two strategies: 1) Reduce resource allocation, that is, if the failure of the target task is due to over-allocation of resources, reduce resource allocation to reduce the task burden; 2) Reschedule resources, that is, migrate the failed target task to other containers with more sufficient resources. In summary, when executing the target task according to the optimal configuration parameters, if the target task execution lags, resource consumption exceeds the threshold, input / output bottlenecks or abnormal behavior occur, the resource allocation to the target task is adjusted based on the incremental adjustment factor.

[0074] It should be noted that the incremental adjustment factor in the above embodiment, that is, the coefficient for incrementally adjusting the resources allocated to the target task (the increment here includes positive increment and negative increment, i.e., decrement), can be obtained based on parameter estimation based on experimental adjustment based on the current resource status of the target task, online learning based on machine learning, or reinforcement learning based on feedback.

[0075] In the above embodiment, the incremental adjustment factor obtained based on the current resource status of the target task is suitable for scenarios with high real-time requirements. Generally, the incremental adjustment factor in this scenario can be obtained by calculating the amount of additional resources required for each unit of progress of the target task. The incremental adjustment factor is obtained based on the parameter estimation adjusted by the experiment. The specific implementation is to run multiple experiments on the same target task, record the task performance under different resource configurations each time, and then analyze the relationship between resource configuration and target task performance (such as execution time, progress, etc.), and use regression method to fit. The incremental adjustment factor obtained by online learning based on machine learning is suitable for complex task scenarios and can dynamically adapt to different task types and execution environments. Specifically, it can be based on the progress of the target task, historical data, real-time monitoring data, etc. to train a supervised learning model (such as linear regression, random forest, etc.), and obtain the incremental adjustment factor by predicting the resource requirements of the target task. As for the incremental adjustment factor obtained by feedback-based reinforcement learning, it is mainly suitable for complex target task scenarios with high dynamics and which cannot be clearly modeled. The specific process is to model the resource adjustment problem as a reinforcement learning problem, whose parameters include state, action, and reward, etc.; then, adjust the resources (for example, increase or decrease CPU, memory, storage) according to the current resource usage status of the target task (for example, CPU, memory, storage, etc.); when the benefit of the target task performance improvement (for example, faster progress, improved resource utilization) is greater than a preset value, the incremental adjustment factor is positive, otherwise, the incremental adjustment factor is set to negative.

[0076] Step S1052: Based on real-time task requirements, resource bottlenecks, task execution phases, and / or target task dependencies, adjust permissions set for the target container.

[0077] In the embodiment of the present application, the permission to adjust the target container setting is based on one or any combination of the following situations:

[0078] 1) Based on real-time task requirements, that is, by monitoring the progress of the target task in real time, if the progress of the target task shows that more permissions are required at the current stage (for example, data needs to be written), the permissions set for the target container can be dynamically adjusted according to the monitoring data.

[0079] 2) Based on resource bottlenecks, i.e., if the target container encounters a resource bottleneck (e.g., CPU, memory, I / O, etc.) and the target task requires performing more operations (e.g., reading more data or making network requests), network or storage access permissions are automatically increased;

[0080] 3) Based on the task execution stage, that is, the target task is often divided into multiple stages during execution. At different stages, the permissions of the target container need to be adjusted. For example, in the initial stage, the target container may only need to access input data (read-only permission) and execute computing tasks (CPU, memory permissions), but in the middle stage, the target container may need temporary storage (write permission), cross-container communication (network permission), etc., and in the final stage, the target container may need to submit results, access external resources, etc., at this time, the permission requirements are further increased;

[0081] 4) Based on the target task dependency, that is, when the target task needs to rely on other services or external resources, for example, the target container may need to access the database, call external APIs, etc. during execution. If the target container currently does not have these permissions (such as database access permissions), it is necessary to dynamically add corresponding permissions according to the needs of the target task.

[0082] In order to further ensure the security of the system, a permission audit mechanism can be added after the permission is dynamically adjusted, and a backtracking and auditing function can be provided for possible permission abuse, that is, the method of the above embodiment can also include: auditing the permission adjustment information of the target container; according to the permission adjustment information and the abnormal permission behavior, notifying the user of the permission abnormality of the target container, suspending the execution of the target task by the target container, or revoking the permission of the target container, wherein the permission adjustment information of the target container includes the adjustment time, the adjustment reason, and the permission status before and after the adjustment, etc. According to the type of abnormal permission behavior (such as permission abuse or unauthorized access), a series of response operations can be automatically executed, including permission revocation (i.e., revoking the excessive permissions of the target task), suspension of the target task (i.e., suspending the execution of the target task and waiting for manual review), and notification mechanism (i.e., sending an alarm to the user to notify the possible abnormal behavior), etc. By combining the abnormal permission behavior with the dynamic permission adjustment information, potential permission abuse and abnormal behavior can be discovered and responded to in a timely manner, ensuring that the system will not be threatened by security when the permission is dynamically adjusted. At the same time, through the automated response mechanism, the security and emergency handling capabilities of the system are improved.

[0083] Step S106: After the target task is completed, the target container is destroyed and the container management strategy is adjusted according to the feedback of the large model.

[0084] On the one hand, since containers are usually created on demand, they no longer need to occupy additional resources after the task is completed. Destroying containers helps to release computing, storage and network resources and avoid resource waste; on the other hand, if the container is not destroyed in time, a large number of idle containers may accumulate in the cluster, affecting scheduling efficiency and may cause uneven resource allocation. After the task is completed, destroying invalid containers can maintain the cleanliness and efficiency of the system. Therefore, in an embodiment of the present application, the target container can be destroyed after the target task is completed. For example, in a container management platform such as Kubernetes, a Pod (containing one or more containers) has a clear life cycle, and the destruction of the container can be triggered when the task is completed by setting the life cycle hook of the Pod, that is, after the target task is completed, the target container can automatically enter the terminated state, and Kubernetes destroys the target container according to the state management of the Pod; monitoring tools can also be used in combination with scheduled tasks to monitor the container status, and the destruction operation is automatically triggered when the target task is completed or the target container enters the "completed" state. As for adjusting the container management strategy based on the feedback from the big model, it can be done by collecting task execution data (including resource usage, permission requirements, execution time, etc.), training the big model to optimize the resource allocation and permission management strategies of future tasks, and then adjusting the resource and permission configuration of the task in real time through reinforcement learning or adaptive optimization algorithms to achieve dynamic optimization.

[0085] From the above attached Figure 1 From the example container management method, it can be seen that after predicting the optimal configuration parameters of the target container, creating the target container and allocating resources to the target container according to the optimal configuration parameters, when the demand changes or abnormal behavior occurs during the execution of the target task according to the optimal configuration parameters, the permissions set and the allocated resources of the target container are dynamically adjusted. On the one hand, the resource allocation of the container can be optimized by predicting the required resource configuration according to the characteristics of the target task; on the other hand, by dynamically adjusting the allocated resources, it can not only ensure that the target container always has sufficient computing, storage, network and other resources during operation, thereby maintaining a high performance level, but also reduce unnecessary resource expenditures and reduce operating costs; thirdly, dynamically adjusting the permissions set for the target container can not only adjust the permissions in real time according to the actual task behavior to ensure the reasonable allocation and use of resources, but also effectively prevent the task from abusing permissions or unauthorized access, thereby improving the security of the system.

[0086] Please refer to the attached Figure 2 , is a container management device provided in an embodiment of the present application, which may include an analysis module 201, a prediction module 202, a creation module 203, a setting module 204, an adjustment module 205 and a destruction module 206, which are described in detail as follows:

[0087] The analysis module 201 is used to analyze the task characteristics of the target task when starting the target task;

[0088] A prediction module 202, used to predict optimal configuration parameters of a target container based on historical data and task characteristics of the target task;

[0089] A creation module 203, used to create a target container and allocate resources to the target container according to the optimal configuration parameters of the target container;

[0090] A setting module 204, used to set permissions of the target container;

[0091] An adjustment module 205 is used to dynamically adjust permissions and allocated resources set for the target container when demand changes or abnormal behaviors occur during the execution of the target task according to the optimal configuration parameters of the target container;

[0092] The destruction module 206 is used to destroy the target container after the target task is completed and adjust the container management strategy according to the feedback of the large model.

[0093] From the above attached Figure 2 It can be seen from the example container management device that after predicting the optimal configuration parameters of the target container, creating the target container and allocating resources to the target container according to the optimal configuration parameters, when demand changes or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters, the permissions set for the target container and the allocated resources are dynamically adjusted. On the one hand, the resource allocation of the container can be optimized by predicting the required resource configuration according to the characteristics of the target task; on the other hand, by dynamically adjusting the allocated resources, it can not only ensure that the target container always has sufficient computing, storage, network and other resources during operation, thereby maintaining a high performance level, but also reduce unnecessary resource expenditures and reduce operating costs; thirdly, dynamically adjusting the permissions set for the target container can not only adjust the permissions in real time according to the actual task behavior to ensure the reasonable allocation and use of resources, but also effectively prevent the task from abusing permissions or unauthorized access, thereby improving the security of the system.

[0094] Figure 3 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 3 As shown, the electronic device 3 of this embodiment mainly includes: a processor 30, a memory 31, and a computer program 32 stored in the memory 31 and executable on the processor 30, such as a program of the container management method. When the processor 30 executes the computer program 32, the steps in the above container management method embodiment are implemented, such as Figure 1 Alternatively, when the processor 30 executes the computer program 32, the functions of each module / unit in the above-mentioned device embodiments are implemented, for example Figure 2The functions of the analysis module 201, the prediction module 202, the creation module 203, the setting module 204, the adjustment module 205 and the destruction module 206 are shown.

[0095] Exemplarily, the computer program 32 of the container management method mainly includes: when starting the target task, analyzing the task characteristics of the target task; predicting the optimal configuration parameters of the target container based on historical data and the task characteristics of the target task; creating a target container and allocating resources to the target container according to the optimal configuration parameters of the target container; setting the permissions of the target container; when the demand changes or abnormal behavior occurs during the execution of the target task according to the optimal configuration parameters of the target container, dynamically adjusting the permissions and allocated resources set for the target container; after the target task is completed, destroying the target container and adjusting the container management strategy according to the feedback of the large model. The computer program 32 can be divided into one or more modules / units, one or more modules / units are stored in the memory 31, and are executed by the processor 30 to complete the present application. One or more modules / units can be a series of computer program instruction segments that can complete specific functions, and the instruction segments are used to describe the execution process of the computer program 32 in the electronic device 3. For example, the computer program 32 can be divided into the functions of an analysis module 201, a prediction module 202, a creation module 203, a setting module 204, an adjustment module 205 and a destruction module 206 (modules in the virtual device), and the specific functions of each module are as follows: an analysis module 201, which is used to perform task characteristic analysis on the target task when starting the target task; a prediction module 202, which is used to predict the optimal configuration parameters of the target container based on historical data and the task characteristics of the target task; a creation module 203, which is used to create a target container and allocate resources to the target container according to the optimal configuration parameters of the target container; a setting module 204, which is used to set the permissions of the target container; an adjustment module 205, which is used to dynamically adjust the permissions and allocated resources set for the target container when demand changes or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters of the target container; a destruction module 206, which is used to destroy the target container after the target task is completed and adjust the container management strategy according to the feedback of the large model.

[0096] The electronic device 3 may include but is not limited to a processor 30 and a memory 31. Those skilled in the art will appreciate that Figure 3 It is only an example of the electronic device 3 and does not constitute a limitation of the electronic device 3. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.

[0097] The processor 30 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0098] The memory 31 may be an internal storage unit of the electronic device 3, such as a hard disk or memory of the electronic device 3. The memory 31 may also be an external storage device of the electronic device 3, such as a plug-in hard disk, a smart memory card (SmartMedia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the electronic device 3. Further, the memory 31 may also include both an internal storage unit of the electronic device 3 and an external storage device. The memory 31 is used to store computer programs and other programs and data required by the electronic device. The memory 31 may also be used to temporarily store data that has been output or is to be output.

[0099] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0100] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0101] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0102] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0103] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0104] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0105] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program of the container management method can be stored in a storage medium. When the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments, that is, when starting the target task, the task characteristics of the target task are analyzed; based on historical data and the task characteristics of the target task, the optimal configuration parameters of the target container are predicted; according to the optimal configuration parameters of the target container, the target container is created and resources are allocated to the target container; the permissions of the target container are set; when the demand changes or abnormal behavior occurs during the execution of the target task according to the optimal configuration parameters of the target container, the permissions set and the allocated resources of the target container are dynamically adjusted; after the target task is completed, the target container is destroyed and the container management strategy is adjusted according to the feedback of the large model. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. Storage media may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, mobile hard disks, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the storage medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, storage media do not include electric carrier signals and telecommunication signals.

[0106] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application is described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some of the technical features therein by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application. The specific implementation methods described above further describe the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only the specific implementation method of the present application, and is not used to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the protection scope of the present invention.

Claims

1. A container management method, characterized in that: The method comprises: When starting a target task, analyzing the target task to obtain the task characteristics of the target task; Predicting optimal configuration parameters of the target container based on historical data and task characteristics of the target task; According to the optimal configuration parameters, create the target container and allocate resources to the target container; According to the task characteristics of the target task, setting the permissions of the target container; When demand changes or abnormal behavior occur during the execution of the target task according to the optimal configuration parameters, dynamically adjust the permissions set for the target container and the allocated resources; After the target task is completed, the target container is destroyed and the container management strategy is adjusted according to the feedback of the large model.

2. The container management method according to claim 1, characterized in that: When starting the target task, analyzing the target task to obtain the task characteristics of the target task includes: Analyzing the resource type and execution time required to execute the target task based on historical data, wherein the historical data includes execution data of the target task or tasks similar to the target task in an actual production environment or a simulation environment; Obtaining permission requirements for the target task by analyzing the source code and dependent libraries of the target task; Based on the analysis results of the source code and dependent libraries of the target task, a permission requirement set of the target task is generated by establishing a permission mapping table.

3. The container management method according to claim 1, characterized in that: The step of predicting the optimal configuration parameters of the target container based on the historical data and the task characteristics of the target task includes: If there is a linear relationship between the task characteristics of the target task and the resource requirements, predicting the optimal configuration parameters of the target container based on the historical data and the regression analysis method; If there is a nonlinear relationship between the task characteristics and resource requirements of the target task, the optimal configuration parameters of the target container are predicted based on the historical data and machine learning.

4. The container management method according to claim 1, characterized in that: The step of setting permissions of the target container according to the task characteristics of the target task includes: The initial permission of the target container is set according to the task characteristics of the target task and based on the principle of least permission, the default role of the target container or the type of the target container.

5. The container management method according to claim 1, characterized in that: When a demand change or abnormal behavior occurs during the execution of the target task according to the optimal configuration parameters, dynamically adjusting the permissions set for the target container and the allocated resources includes: When executing the target task according to the optimal configuration parameters, if the target task is delayed in execution, resource consumption exceeds a threshold, input / output bottlenecks or abnormal behavior occur, adjusting resource allocation to the target task based on an incremental adjustment factor; Based on real-time task requirements, resource bottlenecks, task execution phases, and / or target task dependencies, the permissions set for the target container are adjusted.

6. The container management method according to claim 5, characterized in that: The incremental adjustment factor is obtained based on the current resource status of the target task, based on theoretical model derivation, based on parameter estimation of experimental adjustment, based on online learning based on machine learning, or based on feedback reinforcement learning.

7. The container management method according to claim 5, characterized in that: The method further comprises: Auditing permission adjustment information of the target container; According to the permission adjustment information and the abnormal permission behavior, the user is notified, the execution of the target task by the target container is suspended, or the permission of the target container is revoked.

8. A container management device, characterized in that: The device comprises: An analysis module, used for analyzing the target task to obtain the task characteristics of the target task when starting the target task; A prediction module, used for predicting optimal configuration parameters of a target container based on historical data and task characteristics of the target task; A creation module, used for creating the target container and allocating resources to the target container according to the optimal configuration parameters; A setting module, used to set the permissions of the target container according to the task characteristics of the target task; An adjustment module, configured to dynamically adjust permissions set for the target container and allocated resources when demand changes or abnormal behaviors occur during the execution of the target task according to the optimal configuration parameters; The destruction module is used to destroy the target container after the target task is completed and adjust the container management strategy according to the feedback of the large model.

9. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Vehicle-mounted application deployment method and system based on containerized isolation and dynamic adaptation

    CN122240131A