Method and device for running assembly line and computer readable storage medium

By preconfiguring the admission rules and generating admission nodes in the CICD pipeline, dynamically verifying the results of the code inspection task, the increase in workload and code missed configuration problems caused by manual deployment of code inspection tools is solved, and efficient pipeline operation is achieved.

CN120029631APending Publication Date: 2025-05-23HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311548884.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-20
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art has increased workload due to the manual deployment of code inspection tools on each CICD pipeline, and there is a risk of code missed detection and code missed allocation.

Method used

By preconfiguring the access rules, identify the target standard entry rules corresponding to the pipeline to be deployed, and generate the access node corresponding to the deployment task in the pipeline to dynamically verify the results of the code check task, and avoid manually deploying the inspection tools.

Benefits of technology

It realizes automated entry node generation and code inspection, reduces workload, avoids the risk of missed code detection and misallocation, and improves the operation efficiency of the pipeline.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120029631A_ABST
    Figure CN120029631A_ABST
Patent Text Reader

Abstract

The invention provides an assembly line running method and device and a computer readable storage medium, and the method comprises the steps: obtaining a target admission rule corresponding to a to-be-deployed assembly line from pre-configured admission rules, and carrying out the deployment of the to-be-deployed assembly line under a condition that the to-be-deployed assembly line comprises a deployment task specified by the target admission rule, and generating an access node corresponding to the deployment task in the assembly line to obtain an updated assembly line, according to the embodiment of the invention, through pre-configuring the access rule, when the deployment task including the access rule setting in the assembly line is identified, the task is deployed in the assembly line to realize the generation of the access node, and the code inspection task of the deployment task is verified; thus, there is no need to deploy an inspection tool on each assembly line, and through a mode of dynamically generating the access nodes, missed configuration can be avoided, and the risk of access interception bypassing can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and device for running a pipeline, and a computer-readable storage medium. Background Art

[0002] With the continuous development of Internet technology, continuous integration, continuous delivery, and continuous deployment (CICD) tools are increasingly being used in product development to improve development efficiency. As the CICD pipeline is in use, with the improvement of development efficiency, the code problems introduced by the CICD pipeline are also increasing, such as code security vulnerabilities, code logic vulnerabilities, and code stress test failures. In order to improve product quality, code inspection tools can be deployed on the CICD pipeline to improve the code problems introduced by the CICD pipeline.

[0003] At present, the existing related technology is to manually deploy code checking tools on each CICD pipeline and use the code checking tools to improve the code problems introduced by the CICD pipeline. However, the manual deployment of code checking tools on each CICD pipeline will cause a sharp increase in workload as the number of CICD pipelines continues to increase, and there is a risk of code omission. In addition, when manually deploying code checking tools on the CICD pipeline, there is a risk of code omission when setting deployment tasks before the code checking tools. Summary of the invention

[0004] The embodiments of the present application provide a method, an apparatus, and a computer-readable storage medium for running a pipeline to solve the problems of the prior art of increased workload caused by manually deploying code checking tools on each CICD pipeline, as well as the risks of code missed checks and code mismatches.

[0005] In the first aspect, an embodiment of the present application proposes a method for running a pipeline, the method comprising: obtaining a target access rule corresponding to the pipeline to be deployed from preconfigured access rules for specifying deployment tasks for access checks and code check tasks corresponding to the deployment tasks; determining whether the pipeline to be deployed includes the deployment tasks specified by the target access rule, and if the pipeline to be deployed includes the deployment tasks specified by the target access rule, generating an access node corresponding to the deployment task in the pipeline to obtain an updated pipeline, running the updated pipeline, and intercepting the execution of the deployment task based on the inspection result of the code check task corresponding to the deployment task through the access node corresponding to the deployment task in the updated pipeline. Wherein, the pipeline includes at least one deployment task.

[0006] Based on the method described in the first aspect, the target access rules corresponding to the pipeline to be deployed are identified through pre-configured access rules, and when it is identified that the pipeline to be deployed includes the deployment task set by the target access rules, an access node corresponding to the deployment task is generated in the pipeline to be deployed. Based on the identification of access rules and the identification of deployment tasks specified by the access rules, dynamic generation of access nodes is achieved, and there is no need to manually configure the access nodes on each pipeline, which can avoid missing configurations and reduce the risk of access interception bypass; the code inspection tasks corresponding to the deployment tasks are verified through the dynamically generated access nodes. In this way, there is no need to deploy inspection tools on each pipeline, avoiding the problem of increased deployment workload caused by an increase in the number of pipelines.

[0007] In a possible implementation, the specific implementation is: the preconfigured admission rule specifies the environment label of the deployment task that enters the admission check and the environment label of the code check task corresponding to the deployment task.

[0008] Based on this possible implementation method, the environment label of the deployment task that enters the access check specified in the target access rule can be used to determine whether the pipeline to be deployed includes the deployment task specified in the target access rule. In addition, when the pipeline to be deployed includes the deployment task specified in the target access rule, the environment label of the code check task corresponding to the deployment task specified in the target access rule can be used to determine which code check task results need to be checked in the access node. The environment label can be used to quickly and accurately identify whether the pipeline to be deployed includes the deployment task specified in the target access rule, and which code check task results need to be checked in the access check, thereby improving the accuracy of access interception and the operation efficiency of the pipeline at the same time.

[0009] In one possible implementation, the specific implementation is: the preconfigured access rule also stipulates that there is at least one inspection result for checking whether the code inspection task corresponding to the environmental label in the pipeline meets the preset threshold of the access rule, wherein each preset threshold is set with an environmental label.

[0010] Based on this possible implementation method, in the access check, the preset threshold corresponding to each code check task in the code check task that needs to be checked can be identified through the environment label of the preset threshold. Through the preset threshold corresponding to each code check task, it is detected whether the inspection result of the code check task meets the corresponding preset threshold, providing a quantitative representation for the access check of the code check task, improving the reliability of the access check results, simplifying the access check steps, and improving the operation efficiency of the pipeline.

[0011] In a possible implementation, multiple access rules are preconfigured, and the application scope of each preconfigured access rule is configured, and different preconfigured access rules are configured with different application scopes; from the preconfigured access rules, the target access rule corresponding to the pipeline to be deployed is obtained. The specific implementation is: determine the target application scope of the pipeline to be deployed, and determine the access rule corresponding to the target application scope among the multiple preconfigured access rules as the target access rule.

[0012] Based on this possible implementation method, the target entry rules corresponding to the pipeline to be deployed can be quickly identified through the application scope, without the need to deploy code inspection tools on each pipeline, thereby improving the operation efficiency of the pipeline.

[0013] In one possible implementation, obtaining the target access rules corresponding to the pipeline to be deployed from the preconfigured access rules is specifically implemented as follows: based on the association relationship between the preconfigured access rules and the pipeline set, the access rules corresponding to the pipeline set to be deployed are determined as the target access rules; wherein the association relationship between the preconfigured access rules and the pipeline set is used to indicate the mapping relationship between the pipeline set and the corresponding access rules.

[0014] Based on this possible implementation method, the target entry rules corresponding to the pipeline to be deployed are identified at the pipeline speed, and there is no need to deploy code inspection tools on each pipeline, thereby improving the pipeline operation efficiency.

[0015] In a possible implementation, the specific implementation is: the association relationship between the pre-configured admission rules and the pipeline set is obtained by associating the admission rules configured in response to the admission rule configuration operation with the selected pipeline set.

[0016] Based on this possible implementation method, when configuring the access rules, the configured access rules are associated with the selected pipeline set, and an association relationship between the pre-configured access rules and the pipeline set is established. In this way, when identifying the target access rules corresponding to the pipeline to be deployed from the pre-configured access rules, the access rules corresponding to the pipeline set where the pipeline to be deployed is located can be directly determined as the target access rules corresponding to the pipeline to be deployed, thereby realizing rapid identification of the access rules corresponding to the pipeline and improving the operation efficiency of the pipeline.

[0017] In one possible implementation, the association relationship between the preconfigured access rules and the pipeline set is established in the following manner: in response to an access rule configuration operation, a configuration page view is displayed, and a preconfigured access rule is formed based on the environment tag of the deployment task input in the configuration page view, the environment tag of the code inspection task corresponding to the deployment task, and the preset threshold of the code inspection task; at least one pipeline set information is displayed in the configuration page view, and in response to a selection operation based on the pipeline set information input, a pipeline set corresponding to the preconfigured access rule is obtained; the preconfigured access rule is associated with the pipeline set corresponding to the preconfigured access rule to obtain the association relationship between the preconfigured access rule and the pipeline set.

[0018] Based on this possible implementation method, the environment tag of the deployment task and the environment tag of the code inspection task are input through the configuration page view to form the access rules, and the selected pipeline set is associated with the access rules to form an association relationship between the pre-configured access rules and the pipeline set, thereby achieving the flexibility and applicability of the access rule configuration; at the same time, the access rules are configured through the input operation of the configuration page view to increase the customization of the access rule configuration.

[0019] In one possible implementation, running the updated pipeline is specifically implemented as follows: obtaining the inspection result of the code inspection task corresponding to the deployment task, determining whether the access inspection has been passed based on the inspection result of the code inspection task corresponding to the deployment task, and when the access inspection has been passed, executing the deployment task and continuing to run the updated pipeline; when the access inspection has not been passed, not executing the deployment task and stopping the operation of the updated pipeline.

[0020] Based on this possible implementation method, the inspection result of the code inspection task corresponding to the deployment task is used to determine whether the access check is passed. If and only if the access check is passed, the deployment task is executed to implement access interception of the deployment task and reduce the risk of bypassing the access interception.

[0021] In one possible implementation, determining whether the access check has passed based on the inspection results of the code inspection tasks corresponding to the deployment tasks is specifically implemented as follows: when the inspection results of all the code inspection tasks corresponding to the deployment tasks meet the preset threshold corresponding to the environment tag of the code inspection tasks, it is determined that the access check has passed; when there is at least one code inspection task whose inspection result does not meet the preset threshold, it is determined that the access check has failed.

[0022] Based on this possible implementation method, the inspection results of the code inspection tasks are checked by using the preset threshold corresponding to the environment tag of the code inspection tasks. When the inspection results of all the code inspection tasks corresponding to the deployment tasks meet the preset threshold corresponding to the environment tag of the code inspection tasks, it is determined that the access check has passed, thereby avoiding missed access checks in deployment tasks.

[0023] In one possible implementation, a code inspection task and a verification node corresponding to the code inspection task are deployed in the pipeline; obtaining the inspection result of the code inspection task corresponding to the deployment task is specifically implemented as follows: the verification node executes the code inspection task, obtains the inspection result of the code inspection task, pushes the inspection result of the code inspection task to the access node, and the access node obtains the inspection result of the code inspection task corresponding to the deployment task pushed by the verification node.

[0024] Based on this possible implementation method, the code checking task is executed by the verification node, and the inspection result of the code checking task is pushed to the access node, ensuring that the access node can obtain the inspection result of the code checking task, and by pushing the verification node, the real-time and accuracy of the inspection result of the code checking task obtained by the access node can be ensured.

[0025] In one possible implementation, the specific implementation is as follows: at least one access node corresponding to a deployment task is deployed in the updated pipeline, and each deployment task corresponds to a different environment label; the access node corresponding to each deployment task is used to perform access checks on each code inspection task based on the inspection results of the code inspection task corresponding to the deployment task before each deployment task.

[0026] Based on this possible implementation method, the access nodes corresponding to the deployment tasks with different environment labels are deployed in the updated pipeline to implement access checks for deployment tasks in a variety of different environments, further avoiding the risk of bypassing the access checks.

[0027] In one possible implementation, the specific implementation is as follows: the pipeline includes multiple sub-pipelines, each sub-pipeline corresponds to at least one deployment task, each deployment task corresponds to a different environment label, each sub-pipeline is run, and the inspection results of the code inspection tasks in the deployment tasks under different environment labels are obtained, and the inspection results of the code inspection tasks in the deployment tasks under different environment labels are saved in the indicator lake. When the access node obtains the inspection result of the code inspection task corresponding to the deployment task, it obtains the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline from the indicator lake.

[0028] Based on this possible implementation method, different sub-pipelines push the inspection results of the code inspection tasks in the sub-pipelines to the indicator lake. The access node obtains the inspection results of the code inspection tasks corresponding to the deployment tasks through the indicator lake, which can realize the rapid acquisition of the inspection results of the code inspection tasks and the cross-pipeline application of the inspection results of the code inspection tasks.

[0029] In one possible implementation, saving the inspection results of the code inspection tasks in the deployment tasks under different environment tags in the indicator lake is specifically implemented as follows: for each environment tag, the identification information of the environment tag and the software package corresponding to the deployment task under the environment tag is used as an index, and the inspection result of the code inspection task in the deployment task under the environment tag is used as the value of the index, and the index and the index value are saved in the indicator lake.

[0030] Based on this possible implementation method, the environment tag and the identification information of the software package corresponding to the deployment task under the environment tag are used as the index, the inspection result of the code inspection task in the deployment task under the environment tag is used as the index value, and the index and the index value are saved in the indicator lake. In this way, the inspection result of the code inspection task can be quickly obtained from the indicator lake according to the environment tag and the identification information of the software package corresponding to the deployment task under the environment tag, thereby improving the operation efficiency of the pipeline.

[0031] In one possible implementation, obtaining the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline from the indicator lake is specifically implemented as follows: using the identification information of the software package of the updated pipeline and the environment label of the code inspection task for access inspection specified by the corresponding target entry rule as indexes, querying from the indicator lake to obtain the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline.

[0032] Based on this possible implementation method, the identification information of the software package of the updated pipeline and the environment label of the code inspection task for access inspection specified by the corresponding target entry rule are used as indexes, and the inspection results of the code inspection tasks corresponding to the deployment tasks in the updated pipeline are obtained from the indicator lake, so as to realize fast and accurate query of the inspection results of the code inspection tasks and improve the operation efficiency of the pipeline.

[0033] In a possible implementation, the specific implementation is: the inspection result of the code inspection task stored in the indicator lake is applicable to the access inspection of the deployment task in the first pipeline. Optionally, the first pipeline is any pipeline that includes the deployment task specified by the target entry rule.

[0034] Based on this possible implementation method, for any pipeline that includes a deployment task specified by the target entry rule, the inspection results of the code inspection task can be quickly obtained from the indicator lake during runtime, realizing the cross-pipeline application of the inspection results of the code inspection task, simplifying the steps for obtaining the inspection results of the code inspection task, and improving the operation efficiency of the pipeline.

[0035] In a possible implementation, the specific implementation is as follows: after the deployment task is not executed and the updated pipeline is stopped, the inspection result of the code inspection task corresponding to the deployment task is output, and according to the preset cycle, the identification information of the software package of the updated pipeline and the environment label of the code inspection task for access inspection corresponding to the target standard entry rule are used as indexes to query the indicator lake to obtain the new inspection result of the code inspection task corresponding to the deployment task in the updated pipeline; and whether the access inspection is passed is determined based on the new inspection result of the code inspection task corresponding to the deployment task.

[0036] Based on this possible implementation method, the cross-pipeline application of the inspection results of the code inspection task is realized through the indicator lake. When the access inspection fails, it is only necessary to re-run the sub-pipeline where the code inspection results that do not meet the preset threshold are located, and there is no need to re-run the entire pipeline, which improves the operation efficiency of the pipeline.

[0037] In the second aspect, an embodiment of the present application provides a device for running a pipeline, which can be a computing device cluster that executes a method for running a pipeline, or a computing device in a computing device cluster, or a chip or system on chip in a computing device, or a computing device that executes a method for running a pipeline, and can also be a functional module for implementing the method in the first aspect or any possible implementation of the first aspect in a computing device that executes a method for running a pipeline. The device for running a pipeline can implement the functions performed by the computing device in any possible implementation of the first aspect or the first method, and the functional module can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example: an acquisition module, a deployment module, and an operation module. Optionally, the computing device cluster includes at least one computing device.

[0038] Among them, the acquisition module is used to obtain the target access rules corresponding to the pipeline to be deployed from the preconfigured access rules for specifying the deployment tasks for access checks and the code inspection tasks corresponding to the deployment tasks, wherein the pipeline includes at least one deployment task.

[0039] The deployment module is used to determine whether the pipeline to be deployed includes the deployment task specified by the target entry rule, and if the pipeline to be deployed includes the deployment task specified by the target entry rule, generate an access node corresponding to the deployment task in the pipeline to obtain an updated pipeline, wherein the access node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task.

[0040] The running module is used to run the updated pipeline, intercept the execution of the deployment task based on the inspection result of the code inspection task corresponding to the deployment task through the admission node corresponding to the deployment task in the updated pipeline.

[0041] Specifically, the relevant processing actions of the acquisition module, deployment module and operation module, and their beneficial effects can be referred to in the first aspect or any possible implementation method of the first aspect, and will not be described in detail.

[0042] In the third aspect, a device for running a pipeline is proposed. The device for running a pipeline can be a computing device cluster that executes the method for running a pipeline, or a computing device in a computing device cluster, or a chip or system on chip in a computing device. It can also be a functional module in a computing device that executes the method for running a pipeline, used to implement the method in the first aspect or any possible implementation of the first aspect. The device for running a pipeline can implement the functions performed by the computing device in any possible implementation of the first aspect or the first method mentioned above, and the functional module can be implemented by hardware. In a possible implementation, the device for running a pipeline includes a processor and a memory. Among them, the memory is used to store the computer execution instructions and data necessary for the device for running a pipeline, and the processor is used to execute the computer execution instructions and data necessary for the device for running a pipeline stored in the memory, so that the device for running a pipeline executes the method described in the first aspect or any possible implementation of the first aspect mentioned above.

[0043] In a fourth aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a device for running a pipeline, the device for running the pipeline executes the instructions in the computer program stored in the computer-readable storage medium to execute the method described in the first aspect or any possible implementation of the first aspect.

[0044] Based on the above scheme, the method, device and computer-readable storage medium for running the pipeline in the embodiments of the present application, by pre-configuring access rules, identify the deployment tasks in the pipeline that include access rule settings, deploy the tasks in the pipeline to generate access nodes, and verify the code inspection tasks of the deployment tasks. In this way, there is no need to deploy inspection tools on each pipeline, and by dynamically generating access nodes, the risk of missing configurations and bypassing access interception can be avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 It is a schematic diagram of the threshold execution of the cloud effect pipeline in the prior art;

[0046] Figure 2 It is a schematic diagram of the Azure Pipeline access configuration in the prior art;

[0047] Figure 3 It is a schematic diagram of the configuration of Azure Pipeline in the prior art;

[0048] Figure 4 It is a schematic diagram of an application scenario of the method for running an assembly line provided in an embodiment of the present application;

[0049] Figure 5 It is a schematic diagram of the interface of the pipeline system provided in the embodiment of the present application;

[0050] Figure 6 It is a schematic diagram of storing pipelines in the form of an organization tree provided in an embodiment of the present application;

[0051] Figure 7 It is a schematic diagram of the interface interaction of the pipeline system executing the access rule configuration provided by the embodiment of the present application;

[0052] Figure 8 It is a schematic diagram of the interface interaction for configuring the application scope of the pipeline system executing the access rule provided in the embodiment of the present application;

[0053] Fig. 9 It is a flowchart of the method for running the pipeline provided in the embodiment of the present application;

[0054] Fig.10 is a schematic diagram of a pipeline to be deployed provided in an embodiment of the present application;

[0055] Fig.11 is a schematic diagram of an updated pipeline provided in an embodiment of the present application;

[0056] Fig.12 It is a flowchart of a method for establishing an association relationship between an admission rule and a pipeline set provided in an embodiment of the present application;

[0057] Fig.13 It is an interactive schematic diagram of configuring admission rules through an admission rule configuration center provided in an embodiment of the present application;

[0058] Fig.14 It is a schematic diagram of an updated pipeline performing access check according to an embodiment of the present application;

[0059] Fig.15 It is a schematic diagram of a sub-pipeline provided in an embodiment of the present application;

[0060] Fig.16 It is a schematic diagram of the access check based on the indicator lake provided in the embodiment of the present application;

[0061] Fig.17 It is a schematic diagram of the structure of the device for running the assembly line provided in the embodiment of the present application;

[0062] Fig.18 It is a structural block diagram of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0063] First, some terms used in this application are explained:

[0064] Continuous integration, continuous delivery, and continuous deployment (CICD) tools. CICI tools have continuous integration, continuous delivery, and continuous deployment functions.

[0065] Continuous integration (CI) can refer to the continuous and frequent integration of local code into the main branch and ensuring the availability of the main branch. Continuous delivery (CD) can refer to the continuous and frequent delivery of new versions of software to a production-like environment for testing and product acceptance. Continuous deployment (CD) can refer to the automatic deployment of code to the production environment.

[0066] Pipeline: The software construction project is described through code, from obtaining source code, to automated testing, to vulnerability scanning, to deployment.

[0067] CICD pipeline: The continuous integration & continuous delivery & continuous deployment pipeline can be understood as obtaining source code through continuous integration, performing automated testing and vulnerability scanning on the obtained source code through continuous delivery, and deploying code through continuous deployment. The deployment pipeline refers to the automated form of the process from the software version library to the user's hands. Pipeline technology can refer to a task decomposition technology in which multiple instructions overlap to perform operations when a program or code is executed. This technology can decompose a task into several subtasks that are executed sequentially. Different subtasks are executed by different execution agencies, and these execution agencies can work in parallel at the same time.

[0068] In related technologies, in order to solve code problems such as code security vulnerabilities and code logic vulnerabilities introduced by the CICD pipeline, a cloud-efficient pipeline and a one-stop continuous integration and continuous delivery tool (Azure Pipeline) are proposed.

[0069] Among them, Yunxiao pipeline supports users to configure code inspection tools at any stage, and each inspection tool supports the configuration of threshold interception. Figure 1 FIG. 4 shows a schematic diagram of the threshold execution of the cloud effect pipeline in the prior art. Figure 1 As shown in FIG, before the deployment phase of pipeline XX1, a series of code checking tools are configured in pipeline XX1, and corresponding interception thresholds are configured in the code checking tools. When the actual execution result of the code checking tool's indicator exceeds the set threshold, as shown in FIG. Figure 1 When the code specification scanning result shown in exceeds the threshold, the execution of pipeline XX1 is blocked and subsequent test tasks cannot be continued, thus achieving code problem risk management.

[0070] Azure Pipeline is a tool that can automatically generate and test code projects. It supports all major development languages ​​and project types, and combines continuous integration, continuous delivery, and continuous testing to generate, test, and deliver code to any target production environment. The Azure Pipeline stage supports access and exit capabilities. In access / exit, you can configure access control. By configuring check items in access control, you can implement access / exit interception. Figure 2 As shown, if the stage is a deployment task, set the pipeline admission interception stage in the admission configuration, set the code compliance check interception item access control, and the access control value corresponding to the code compliance check interception item access control in the admission configuration. When the pipeline is executed to this point, the code check interception item verification fails, and the deployment task cannot be executed backward to achieve release quality control; if the stage is a code check task, such as Figure 3As shown, configure the pipeline's exit interception stage in the exit, set the interception item access control of the code standardization check and the access control value corresponding to the interception item access control of the code standardization check in the exit configuration. When the pipeline executes to this point, if the code check interception item verification fails, the task cannot be executed backwards to achieve release quality control.

[0071] However, whether it is the cloud effect pipeline or the azure pipeline, developers or managers are required to configure code checking tools or intercept access control on each pipeline. As the number of pipelines increases, the configuration workload also increases sharply. Moreover, there is a risk of missing configuration when manually configuring code checking tools or intercepting access control on the pipeline, and there is a risk of code checking interception bypass when the pipeline deployment stage is scheduled before the code checking stage.

[0072] Based on this, in order to solve the problems of increased workload and the risk of missed detection and misconfiguration caused by manually deploying code checking tools on each pipeline in the prior art, the embodiments of the present application provide a method, device and computer-readable storage medium for running a pipeline. By pre-configuring access rules, when a deployment task including an access rule setting is identified in the pipeline, the task is deployed in the pipeline to generate an access node, and the code checking task of the deployed task is verified. In this way, there is no need to deploy checking tools on each pipeline, and by dynamically generating access nodes, the risk of missed configuration and access interception bypass can be avoided.

[0073] The following will introduce the method, device and computer-readable storage medium for running the pipeline provided by the embodiments of the present application in conjunction with specific embodiments.

[0074] In order to better illustrate the method for running a pipeline provided in the embodiment of the present application, taking application publishing as an example, an application scenario of the method for running a pipeline is provided, such as Figure 4 As shown, Figure 4 It is a schematic diagram of an application scenario of the method for running a pipeline provided in an embodiment of the present application. The application scenario shown includes a code repository 410, a pipeline system 420, developers / testers, and managers.

[0075] The code repository 410 is used to store code files. The code repository 410 can be deployed in a storage device or on a cloud platform.

[0076] Among them, the pipeline system 420 is used to respond to pipeline construction operations input by developers / tester personnel, access the code repository 410, obtain (or pull) code files from the code repository 410, create pipelines based on the obtained code files, store constructed pipelines, respond to access rule configuration operations input by managers, configure access rules for pipelines, and run pipelines in response to pipeline running operations input by developers / tester personnel.

[0077] It should be understood that the pipeline described in this application includes but is not limited to the CICD pipeline, and may also be other pipelines, such as the CI pipeline, CI / CD pipeline, CD pipeline, Development and Operations (DevOps) pipeline, etc.

[0078] In some embodiments, Figure 4 As shown, the pipeline system 420 includes a management end 4201, a development / test end 4202, an indicator lake 4203, and a pipeline database 4204. The management end 4201 communicates with the pipeline database 4204, the development / test end 4202 communicates with the indicator lake 4203 and the pipeline database 4204, the management end 4201 is used to respond to the access rule configuration operation input by the management personnel, configure the access rule, the development / test end 4202 is used to respond to the pipeline construction operation input by the development / test personnel, access the code warehouse 410, pull the code file from the code warehouse 410, create a pipeline based on the acquired code file, store the constructed pipeline, push the constructed pipeline to the pipeline database 4204, and respond to the pipeline operation input by the development / test personnel, pull the pipeline to be deployed from the pipeline database 4204 and run it.

[0079] Specifically, the development / testing end 4202 creates a pipeline in response to the pipeline building operation input by the development / testing personnel, and pushes the pipeline to the pipeline database 4204; the management end 4201 configures the access rules and the application scope of the access rules in response to the access rule configuration operation input by the management personnel; the development / testing end 4202 responds to the pipeline running operation input by the development / testing personnel, and when running the pipeline to be deployed in the pipeline database 4204, identifies the pipeline to be deployed from the access rules pre-configured by the management end 4201 and the application scope of the pre-configured access rules. The application scope corresponds to the target access rule, and it is identified whether the pipeline to be deployed includes the deployment task specified by the target access rule. If the pipeline to be deployed includes the deployment task specified by the target access rule, an access node corresponding to the deployment task is generated in the pipeline, and an updated pipeline is obtained. The updated pipeline is run, and the inspection result of the code inspection task in the updated pipeline is pushed to the indicator lake 4203. When the updated pipeline runs to the access node, the result of the code inspection task that needs to be inspected for access is pulled from the indicator lake 4203 to perform an access check.

[0080] Among them, code inspection tasks may include but are not limited to code style detection, code security detection and code unit inspection. Among them, code style detection may include but are not limited to code reliability detection, code maintainability detection and code duplication detection. Code security detection may include but are not limited to the number of code vulnerabilities detection, code security hotspot review, etc. Code unit detection may include but are not limited to detection of test case coverage.

[0081] Among them, code inspection tasks may include but are not limited to code integration detection, code stress detection, code performance detection, etc.

[0082] Among them, the application scope corresponding to the access rule is used to determine the pipeline to which the access rule can be applied. In some embodiments, the application scope can be an application service. For example, taking the application scope of the access rule as application service A, when the application service corresponding to the pipeline to be deployed is application service A, the pipeline to be deployed needs to apply the access rule. In some embodiments, the application scope can be the department information of the pipeline. For example, taking the application scope of the access rule as department B, when the department information of the pipeline to be deployed is department B, the pipeline to be deployed needs to apply the access rule.

[0083] In one possible implementation, the management end 4201 and the development / test end 4202 can be deployed in the same device. In the case where the management end 4201 and the development / test end 4202 are deployed in the same device, the management end 4201 and the development / test end 4202 can be the names of the same client when providing different services. For example, when the client responds to the pipeline build operation, the client acts as the development / test end 4202, and when the client responds to the access rule configuration operation, the client acts as the management end 4201. In the case where the management end 4201 and the development / test end 4202 are deployed in the same device, the management end 4201 and the development / test end 4202 can also be different clients. In another possible implementation, the management end 4201 and the development / test end 4202 can also be deployed in different devices.

[0084] As an example but not limitation, when the management end 4201 and the development / test end 4202 are deployed on the same device, the management end 4201 and the development / test end 4202 can be the same client and named when providing different services, such as Figure 5 As shown in Figure (a), the interface view of the pipeline system 420 is provided with a pipeline construction function control, an access rule configuration function control and a pipeline operation function control.

[0085] As an example but not a limitation, when the management end 4201 and the development / test end 4202 are deployed on the same device, the management end 4201 and the development / test end 4202 are different clients. Figure 5 As shown in FIG. 4B , the interface view of the management terminal 4201 is provided with an access rule configuration function control, such as Figure 5 As shown in Figure (c), the interface view of the development / test end 4202 is provided with a pipeline construction function control and a pipeline operation function control.

[0086] Among them, the pipeline construction function control can be used to trigger the execution of pipeline construction in response to user operations (such as click operations). The access rule configuration function control can be used to trigger the execution of access rule configuration in response to user operations. The pipeline operation function control can be used to trigger the execution of pipeline operation in response to user operations.

[0087] For example, developers / tester can input pipeline build operations through pipeline build function control, developers / tester can input pipeline run operations through pipeline run function control, and managers can input access rule configuration operations through access rule configuration function control.

[0088] In the case where the development / testing personnel input the pipeline construction operation through the pipeline construction function control, the development / testing end 4202 responds to the pipeline construction operation, obtains the configuration parameters required to build the pipeline, accesses the code warehouse 410 according to the configuration parameters, pulls the code file corresponding to the pipeline construction instruction from the code warehouse 410, builds the pipeline based on the pulled code file and the configuration parameters, and associates the application service corresponding to the pipeline. Among them, the configuration parameters include but are not limited to introduction, post-script, product, pre-script, cache, mirror, retry times, service, runner, application service corresponding to the pipeline, etc. Among them, the pipeline construction operation is used to instruct the pipeline system 420 to build the pipeline.

[0089] Optionally, the development / testing end 4202 can configure the global configuration information of the pipeline according to the configuration parameters, construct the job information of the pipeline according to the global configuration information, and determine the pipeline file according to the job information. The pipeline file is used to store the execution tasks and execution pipelines included in the pipeline. The execution tasks include but are not limited to deployment tasks and code inspection tasks.

[0090] In a possible implementation, when constructing the job information of the pipeline according to the global configuration information, a single job configuration form can be constructed according to the global configuration information, the stage parameters of the single job configuration form can be configured to obtain the stage information corresponding to the single job, and the multiple stages corresponding to the multiple jobs are aggregated to form the job information of the pipeline. The stage information includes but is not limited to: installation information, deployment information, and image building information, wherein the deployment information includes the deployment environment, the included code inspection tasks, and the environment of the code inspection tasks; the single job configuration form includes but is not limited to: job name, run script, stage parameters, image, runner, variables, trigger conditions, dependencies, integration templates, products, pre-scripts, etc. The deployment environment includes but is not limited to the development environment, test environment, verification environment, and production environment. The environment of the code inspection task includes but is not limited to the development environment, test environment, and verification environment.

[0091] It is understandable that each pipeline can have multiple jobs, and the execution order of these jobs is determined by the stage in which they are located. In each stage, at least one job combination forms an execution task. Exemplarily, taking the deployment task as an example, according to the different deployment environments in the stage information, the deployment tasks in the pipeline include but are not limited to the deployment tasks of the development environment, the deployment tasks of the test environment, the deployment tasks of the verification environment, and the deployment tasks of the production environment, and the deployment tasks of the development environment, the deployment tasks of the test environment, the deployment tasks of the verification environment, and the deployment tasks of the production environment are executed in sequence. It is understandable that the deployment task of the development environment is to deploy the code file to the development environment, and perform the code inspection task on the code file in the development environment. The deployment task of the test environment is to deploy the code file to the test environment, and perform the code inspection task on the code file in the test environment. The deployment task of the verification environment is to deploy the code file to the verification environment, and perform the code inspection task on the code file in the verification environment. The deployment task of the production environment is to deploy the code file to the production environment, run the code file in the production environment, and realize the application service corresponding to the code file.

[0092] In one possible implementation, after constructing the pipeline, the pipeline system pushes the created pipeline to the pipeline database 4204 , for example, stores it in the pipeline database 4204 .

[0093] To facilitate the management and query of the pipeline, the pipeline can be stored in the pipeline database 4204 according to the category to which the pipeline belongs. For example, the pipeline can be classified according to the application service corresponding to the pipeline, and the application service corresponding to the pipeline and the pipeline file of the pipeline can be associated / correspondingly stored in the pipeline database 4204.

[0094] For example, the pipelines may be classified according to the department information to which the pipelines belong, and the department information to which the pipelines belong and the pipeline files of the pipelines may be stored in the pipeline database 4204. The department information may be department information of the department to which the development / testing personnel who construct the pipelines belong, such as the department name and department ID of the department to which the development / testing personnel who construct the pipelines belong.

[0095] For example, the pipelines may be stored in the pipeline database 4204 in the form of a linked list, or in the form of a key-value pair. For example, taking the example of storing the pipelines in the pipeline database 4204 in the form of a key-value pair, the application service corresponding to the pipeline or the department information to which the pipeline belongs is used as the key of the key-value pair, and the pipeline file of the pipeline is used as the value of the key-value pair to construct a set of key-value pairs, and the constructed key-value pairs are stored in the pipeline database 4204.

[0096] For example, the pipelines may also be stored in the pipeline data 4204 in the form of an organizational tree. For example, the pipelines may be classified according to the department information to which the pipelines belong. Figure 6 As shown, the root node "XX" is connected to two leaf nodes "Department A" and "Department B". The department information of pipeline 1 and pipeline 2 is Department A. The pipeline files corresponding to pipeline 1 and pipeline 2 are stored in the branch of Department A. The department information of pipeline 3 and pipeline 4 is Department B. The pipeline files corresponding to pipeline 3 and pipeline 4 are stored in the branch of Department B.

[0097] Among them, when the management personnel inputs the access rule configuration operation through the access rule configuration function control, the management end 4201 responds to the access rule configuration operation based on the input of the access rule configuration function control, obtains the environment label of the access rule, the environment label of the code inspection task, and the threshold of the inspection result, generates the access rule, determines the application scope corresponding to the access rule, and associates the access rule with the application scope corresponding to the access rule.

[0098] The environment label described in this application may refer to the environment corresponding to the deployment task in the pipeline, the environment corresponding to the execution task in the pipeline, or the environment corresponding to the code checking task in the pipeline. Environment labels include but are not limited to Alpha, Beta, Gamma, and Prod, where the environment label Alpha represents the development environment, the environment label Beta represents the test environment, the environment label Gamma represents the verification environment, and the environment label Prod represents the production environment. For example, a deployment task with the environment label Prod represents a deployment task in the production environment.

[0099] Specifically, the environment tag of the admission rule is used to intercept the deployment tasks in the pipeline that are consistent with the environment tag of the admission rule. The environment tag of the code inspection task is used to determine which code inspection task's inspection results need to be inspected for admission in the admission rule.

[0100] Among them, the threshold of the inspection result is used to determine whether the inspection result of the code inspection task that needs to be inspected for access meets the access rules. It is understandable that when the inspection result of the code inspection task that needs to be inspected for access meets the preset threshold, the deployment task is executed. Exemplarily, taking the environment label of the access rule as "Prod" as an example, that is, the deployment task for access inspection is the deployment task of the production environment, when the pipeline runs to the deployment task of the production environment, the execution of the pipeline is stopped, and the inspection result of the code inspection task that needs to be inspected for access is inspected for access according to the preset threshold set in the access rule and the environment label of the code inspection task. When the inspection result of the code inspection task that needs to be inspected for access meets the preset threshold, the code file is deployed to the production environment. When the inspection result of the code inspection task that needs to be inspected for access does not meet the preset threshold, the execution of the pipeline continues to be stopped.

[0101] Among them, the threshold of the inspection result can be one or more of a specific value, a value range, a format, and a field. It is understandable that the threshold of the inspection result is used to determine whether the value of the inspection result of the code inspection task satisfies the value specified in the threshold, or whether it satisfies the value range corresponding to the threshold. The threshold of the inspection result is also used to determine whether the data format of the inspection result of the code inspection task is consistent with the data format specified in the threshold. The threshold of the inspection result can also be used to determine whether there is data in the inspection result of the code inspection task that is consistent with the field specified by the threshold, etc.

[0102] It can be understood that when the threshold of the inspection result is used to determine whether the numerical value of the inspection result of the code inspection task satisfies the numerical value specified in the threshold, or whether it satisfies the numerical range corresponding to the threshold, when the numerical value of the inspection result of the code inspection task matches the numerical value specified in the threshold, or the numerical range corresponding to the threshold, it is determined that the inspection result of the code inspection task that requires access inspection meets the preset threshold.

[0103] In a possible implementation, the match may be that the value of the inspection result of the code inspection task is less than or equal to the value specified in the threshold, or the value of the inspection result of the code inspection task is within the value range specified in the threshold. For example, when the code inspection task is code repetition rate inspection, when the repetition rate of the code inspection task is less than or equal to the repetition rate threshold specified in the threshold, or when the repetition rate of the code inspection task is within the repetition rate range specified in the threshold, it is determined that the value of the inspection result of the code inspection task matches the value specified in the threshold.

[0104] In another possible implementation, the match may also be that the numerical value of the inspection result of the code checking task is greater than the numerical value specified in the threshold, or the numerical value of the inspection result of the code checking task exceeds the numerical range specified by the threshold. For example, when the code checking task is a code reliability check, when it is determined that the reliability parameter of the code checking task is greater than the reliability parameter specified in the threshold, or when it is determined that the reliability parameter of the code checking task exceeds the reliability parameter range specified in the threshold, it is determined that the numerical value of the inspection result of the code checking task matches the numerical value specified in the threshold.

[0105] As an example and not limitation, Figure 7 As shown in Figure (a) in the figure, click the access rule configuration function control set in the current interface view to display the configuration page view. The environment label control of the deployment task that can configure the access rule is displayed in the configuration page view, such as Figure 7 As shown in Figure (b), the configuration page view displays the "Beta" environment label control, the "Gamma" environment label control, and the "Prod" environment label control; in response to the triggering operation of the environment label control, the environment label of the access rule is selected. For example, the environment label of the access rule is "Prod". Figure 7 As shown in Figure (c) in the configuration page view, the code review task before the deployment task of the pipeline in the "Prod" environment and the environment label of the code review task are displayed. Figure 7 The code inspection tasks shown in Figure (c) include: cloud test (cloudtest) tasks for the Alpha environment, variable scan (virusscan) tasks for the Alpha environment, cloud test tasks for the Beta environment, variable scan tasks for the Beta environment, cloud test tasks for the Gamma environment, and variable scan tasks for the Gamma environment; in response to the selection operation of the code inspection task, the code inspection task that needs to be access-checked when the deployment task of the "Prod" environment is intercepted is determined, and the following is generated: Figure 7 The admission rule shown in Figure (d) represents: intercepting the deployment task of the "Prod" environment in the pipeline, and performing admission checks on the corresponding inspection results of the cloud test task of the Alpha environment, the variable scanning task of the Alpha environment, the cloud test task of the Beta environment, the variable scanning task of the Beta environment, the cloud test task of the Gamma environment, and the variable scanning task of the Gamma environment.

[0106] In one possible implementation, the application scope of the admission rule may be determined after the admission rule is generated. In another possible implementation, the application scope of the admission rule may be configured before the admission rule is generated.

[0107] For example, after generating the access rules, configure the application scope of the access rules, such as Figure 8 As shown, the configuration page view shows Figure 7 Configured access rules, such as Figure 8 In Figure (a), the configuration page view has function controls: "Application scope configuration", "Return" and "Cancel". Click the "Application scope configuration" function control to display the pipeline view stored in the form of an organization tree in the current interface view, such as Figure 8 As shown in Figure (b), the root node "XX" is connected to two leaf nodes "Department A" and "Department B". "Department A" includes pipeline 1 and pipeline 2, and "Department B" includes pipeline 3 and pipeline 4. In response to the selection operation of the application scope, the application scope of the access rule is configured as "Department B", which will be Figure 7 The configured access rules are applied to pipelines 3 and 4 under "Department B", such as Figure 8 As shown in Figure (c) of the figure, when "Department B" includes pipeline 3 and pipeline 4, they need to comply with the following when running. Figure 7 Configured access rules.

[0108] Understandable, Figure 8 The function control "Return" in (a) of FIG. 1 can be used to return to the previous interface view. For example, click Figure 8 The function control "Return" in Figure (a) in the configuration page view displays the code inspection task before the deployment task of the environment tag specified by the access rule and the environment tag of the code inspection task. For example, click Figure 8 The function control "Return" in Figure (a) in FIG. 1 shows the environment label control of the deployment task for which the admission rule can be configured in the configuration page view, such as Figure 7 As shown in Figure (b).

[0109] Understandable, Figure 8 The function control "Cancel" in (a) of FIG. 1 can be used to cancel the admission rule configuration. For example, click Figure 8 Click the "Cancel" function in (a) to close the configuration page view. The output is as follows Figure 5 Figure (a), or Figure 5 The interface view shown in Figure (b) is shown in Figure 1. For example, click Figure 8 The function control "Cancel" in Figure (a) cancels the access rule configuration operation and the output is as follows Figure 7 The configuration interface view is shown in Figure (a) of the figure. Figure 8After clicking "Cancel" on the function control in (a) of the figure, a prompt pop-up window is output in the current page view, and the prompt pop-up window view displays the prompt information "Cancel access rule configuration" and the function controls "Confirm" and "Cancel". It can be understood that in response to the click operation of the "Confirm" function control in the prompt pop-up window view, the operation of canceling the access rule configuration is executed, and in response to the click operation of the "Cancel" function control in the prompt pop-up window view, the prompt pop-up window view is closed and the display continues. Figure 8 The interface view shown in Figure (a).

[0110] In a possible implementation, after completing the configuration of the access rules, the pipeline system associates the access rules with the application scope corresponding to the access rules. Exemplarily, the application scope corresponding to the access rules can be marked. For example, taking the application scope of the access rules as "Department B" as an example, the leaf node "Department B" is marked in the pipeline database. Exemplarily, the pipelines within the application scope corresponding to the access rules can be marked. For example, taking the application scope of the access rules as "Department B" as an example, the pipelines under "Department B" in the pipeline database are marked.

[0111] In which, when the development / testing personnel input the pipeline operation through the pipeline operation function control, the pipeline system responds to the pipeline operation operation input based on the pipeline operation function control, determines the pipeline to be deployed, obtains the target access rule corresponding to the pipeline to be deployed from the pre-configured access rules, and generates the access node corresponding to the deployment task in the pipeline when the pipeline to be deployed includes the deployment task specified by the target access rule, obtains the updated pipeline, runs the updated pipeline, and checks the inspection results of the code inspection task that needs to be inspected for access before the deployment task is executed through the access node, and executes the deployment task when the inspection result of the code inspection task meets the preset threshold set in the access rule. In which, the access node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task.

[0112] In a possible implementation, the pipeline system is further provided with an indicator lake, which is used to store the inspection results of the code inspection tasks in the pipeline. When the pipeline is running, the inspection results of the code inspection tasks of the pipeline are pushed to the indicator lake. When running the updated pipeline, the pipeline system pulls the inspection results of the code inspection tasks from the indicator lake.

[0113] based on Figure 4 The application scenario provided, the embodiment of the present application provides a method for running a pipeline, such as Fig. 9 As shown, Fig. 9: is a flowchart of a method for running a pipeline provided in an embodiment of the present application. The method for running a pipeline shown includes at least steps S210 to S230, which are described in detail as follows:

[0114] Step S210: Obtain the target admission rule corresponding to the pipeline to be deployed from the pre-configured admission rules.

[0115] The pre-configured access rules are used to specify the deployment tasks for access checks and the code check tasks corresponding to the deployment tasks. For the description and configuration of the access rules, please refer to Fig.12 The embodiments provided, or referring to the above embodiments in which the administrator inputs the access rule configuration operation through the access rule configuration function control, and Figure 7 , Figure 8 The access rule configuration example provided is not described in detail in this application.

[0116] Wherein, the pipeline may include at least one deployment task. For example, Fig.10 As shown, Fig.10 : is a schematic diagram of the pipeline provided by the embodiment of the present application. The pipeline shown includes, from the beginning to the end, the deployment task of the Alpha environment, the verification task in the Alpha environment, the deployment task of the Beta environment, the verification task in the Beta environment, the verification task in the Gamma environment, the verification task in the Gamma environment, and the deployment task of the Prod environment. Among them, the verification task is used to perform code inspection and obtain the inspection result, such as Fig. 9 As shown, the verification tasks in the Alpha environment include code checking of the cloud test tasks in the Alpha environment and code checking of the variable scanning tasks in the Alpha environment.

[0117] In some implementations, when obtaining the target admission rule corresponding to the pipeline to be deployed, the pipeline information to be deployed may be obtained, and based on the pipeline information, the target admission rule corresponding to the pipeline to be deployed may be obtained from the preconfigured admission rules.

[0118] The pipeline information includes one or more of the pipeline name, pipeline identifier, pipeline application service, identification information of the software package corresponding to the pipeline, the range of the pipeline, pipeline identifier, and code path. The pipeline identifier is used to indicate the identification information of the access rule set by the pipeline. The identification information of the access rule can be the name of the access rule, the configuration time, etc.

[0119] For example, based on the pipeline identifier to be deployed, the admission rule whose identification information matches the pipeline identifier can be obtained from the preconfigured admission rules, and the admission rule whose identification information matches the pipeline identifier can be determined as the target admission rule corresponding to the pipeline to be deployed.

[0120] For example, the application scope of the preconfigured access rules can be queried according to the scope of the pipeline to be deployed, and the access rules that match the application scope of the preconfigured access rules with the scope of the pipeline to be deployed are determined as the target access rules corresponding to the pipeline to be deployed.

[0121] Step S220, when the pipeline to be deployed includes the deployment task specified by the target entry rule, an entry node corresponding to the deployment task is generated in the pipeline to obtain an updated pipeline.

[0122] The admission node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task.

[0123] In some implementations, an inspection task is deployed in the admission node to inspect the inspection results of the code inspection task specified by the admission rule.

[0124] For example, the deployment tasks corresponding to the target entry rules can be compared with the deployment tasks in the pipeline to be deployed to determine whether the pipeline to be deployed includes the deployment tasks specified by the target entry rules; if the pipeline to be deployed includes the deployment tasks specified by the target entry rules, an access node corresponding to the deployment tasks is generated in the pipeline to obtain an updated pipeline; if the pipeline to be deployed does not include the deployment tasks specified by the target entry rules, the pipeline is directly run.

[0125] For example, the stage information of the deployment tasks that need to enter the access check can be set in the access rules. The stage information of the deployment tasks that need to enter the access check in the target access check is compared with the stage information of each deployment task in the pipeline to be deployed to determine whether the pipeline to be deployed includes the deployment tasks specified by the target access rules.

[0126] It can be understood that when there is a deployment task in the pipeline to be deployed whose stage information is consistent with the stage information of the deployment task that needs to enter the access check in the target standard access check, it is determined that the pipeline to be deployed includes the deployment tasks specified by the target standard access rules; when there is no deployment task in the pipeline to be deployed whose stage information is consistent with the stage information of the deployment task that needs to enter the access check in the target standard access check, it is determined that the pipeline to be deployed does not include the deployment tasks specified by the target standard access rules.

[0127] It is understandable that directly running the pipeline can be to execute the tasks in the pipeline in sequence. Fig.10 Taking the provided pipeline as an example, directly running the pipeline will execute the deployment task of the Alpha environment, the verification task in the Alpha environment, the deployment task of the Beta environment, the verification task in the Beta environment, the verification task in the Gamma environment, the verification task in the Gamma environment, and the deployment task of the Prod environment in sequence.

[0128] For example, the deployment tasks and code inspection tasks in the pipeline are both set with environment tags. To facilitate identification of whether there are deployment tasks specified by the target access rules corresponding to the pipeline in the pipeline, the access rules store the environment tags of the deployment tasks that need to enter the access check and the environment tags of the code inspection tasks that need to be inspected in the access check in the access check in the access rules when pre-configuring the access rules. After determining the target access rules corresponding to the pipeline to be deployed, the environment tags of the deployment tasks that enter the access check set in the target access rules are compared with the environment tags of each deployment task in the pipeline to be deployed to determine whether the pipeline to be deployed includes the deployment tasks specified by the target access rules. When it is determined that the pipeline to be deployed includes the deployment tasks specified by the target access rules, an access node corresponding to the deployment task is generated in the pipeline, and an inspection task is generated in the access node according to the environment tags of the code inspection tasks that need to be inspected in the access check set in the target access rules. Each inspection task corresponds to a code inspection task under an environment tag.

[0129] It can be understood that when there is a deployment task in the pipeline to be deployed whose environment label is consistent with the environment label of the deployment task entering the access check in the target access rule, it is determined that the pipeline to be deployed includes the deployment task specified by the target access rule; when there is no deployment task in the pipeline to be deployed whose environment label is consistent with the environment label of the deployment task entering the access check in the target access rule, it is determined that the pipeline to be deployed does not include the deployment task specified by the target access rule.

[0130] As an example and not a limitation, in the case of determining whether the pipeline to be deployed includes the deployment task specified by the target entry rule through the environment tag, Fig.10 Take the provided pipeline as an example. Fig.10When the deployment task corresponding to the target entry rule corresponding to the provided pipeline is the deployment task of the Prod environment, and the code inspection task corresponding to the target entry rule is the cloud test task of the Alpha environment, the variable scanning task of the Alpha environment, the cloud test task of the Beta environment, the variable scanning task of the Beta environment, the cloud test task of the Gamma environment, and the variable scanning task of the Gamma environment, an admission node is generated before the deployment task of the Prod environment in the pipeline, and the cloud test inspection task of the Alpha environment, the variable scanning inspection task of the Alpha environment, the cloud test inspection task of the Beta environment, the variable scanning inspection task of the Beta environment, the cloud test inspection task of the Gamma environment, and the variable scanning inspection task of the Gamma environment are generated in the admission node based on the code inspection task corresponding to the target entry rule, forming the following: Fig.11 The updated pipeline is shown.

[0131] Step S230, running the updated pipeline.

[0132] Among them, run the updated pipeline and execute according to the execution tasks of each stage of the updated pipeline. When the updated pipeline executes to the access node, stop the pipeline operation, execute the inspection task in the access node, and perform access check on the inspection result of the code inspection task. When the inspection result of the code inspection task passes the access check, execute the deployment task and continue to run the updated pipeline. When there is at least one code inspection task whose inspection result fails the access check, do not execute the deployment task and continue to stop the operation of the updated pipeline.

[0133] In a possible implementation, the admission rule includes at least one preset threshold; the preset threshold is set with an environment tag, and the preset threshold is used to check whether the inspection result of the code inspection task corresponding to the environment tag in the pipeline meets the admission rule. The preset threshold may include but is not limited to a value, a value range, a reference format, and a reference field.

[0134] For example, when performing an access check on the inspection results of each code inspection task, the preset threshold corresponding to each code inspection task is determined based on the environment tag of each code inspection task and the environment tag of the preset threshold, and the inspection result of each code inspection task is compared with the preset threshold corresponding to the code inspection task. If the inspection result of each code inspection task meets the preset threshold corresponding to each code inspection task, it is determined that the access check has passed; if there is at least one code inspection task whose inspection result does not meet the preset threshold corresponding to the code inspection task, it is determined that the access check has failed.

[0135] Among them, when the preset threshold is a numerical value or a numerical range, if the inspection result of the code inspection task matches the corresponding preset threshold, it is determined that the inspection result of the code inspection task meets the corresponding preset threshold; if the inspection result of the code inspection task does not match the corresponding preset threshold, it is determined that the inspection result of the code inspection task does not meet the corresponding preset threshold.

[0136] Exemplarily, taking the variable scanning of the Alpha environment as an example, when the number of code vulnerabilities in the variable scanning of the Alpha environment is detected, when the inspection result is less than or equal to the preset threshold, or the inspection result of the code inspection task is within the numerical range specified by the preset threshold, it is determined that the inspection result matches the corresponding preset threshold; when the inspection result is greater than the preset threshold, or the inspection result of the code inspection task exceeds the numerical range specified by the preset threshold, it is determined that the inspection result does not match the corresponding preset threshold.

[0137] Among them, when the preset threshold is a benchmark format, if the inspection result of the code inspection task is consistent with the benchmark format specified in the corresponding preset threshold, it is determined that the inspection result of the code inspection task meets the corresponding preset threshold; if the inspection result of the code inspection task is inconsistent with the benchmark format specified in the corresponding preset threshold, it is determined that the inspection result of the code inspection task does not meet the corresponding preset threshold.

[0138] Among them, when the preset threshold is a reference field, if there is a field in the inspection result of the code checking task that is consistent with the reference field specified in the corresponding preset threshold, then it is determined that the inspection result of the code checking task meets the corresponding preset threshold; if there is no field in the inspection result of the code checking task that is consistent with the reference field specified by the corresponding preset threshold, then it is determined that the inspection result of the code checking task does not meet the corresponding preset threshold.

[0139] For example, Fig.11Taking the updated pipeline provided as an example, when the updated pipeline runs to the deployment task of the Prod environment, it will perform access checks on the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scan of the Alpha environment, the inspection results of the cloud test of the Beta environment, the inspection results of the variable scan of the Beta environment, the inspection results of the cloud test of the Gamma environment, and the inspection results of the variable scan of the Gamma environment; if the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scan of the Alpha environment, the inspection results of the cloud test of the Beta environment, the inspection results of the variable scan of the Beta environment, the inspection results of the cloud test of the Gamma environment, If the inspection results of the variable scans of the Gamma environment all meet their corresponding preset thresholds, it is determined that the access checks have passed, and the deployment tasks of the Prod environment are executed, and the updated pipeline continues to run; if there is at least one inspection result that does not meet the corresponding preset thresholds among the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scans of the Alpha environment, the inspection results of the cloud test of the Beta environment, the inspection results of the variable scans of the Beta environment, the inspection results of the cloud test of the Gamma environment, and the inspection results of the variable scans of the Gamma environment, it is determined that the access check has failed, the deployment tasks of the Prod environment are not executed, and the updated pipeline continues to stop running.

[0140] In some embodiments, when it is determined that the access check fails, an inspection report can be generated based on the code inspection task whose inspection results do not meet the preset threshold, and the inspection report can be output so that the development / testing personnel can repair the deployed pipeline according to the inspection report and re-execute the above steps S210 to S230 to re-run the repaired pipeline.

[0141] Among them, the way to repair the pipeline to be deployed can be to repair the script file and code file of the pipeline to be deployed.

[0142] In some other embodiments, when it is determined that the access check fails, the pipeline can be automatically repaired based on the inspection results to form a repaired pipeline, and the above steps S210 to S230 can be re-executed to re-run the repaired pipeline.

[0143] For example, when automatically repairing the pipeline based on the inspection results, you can pre-set repair specifications for different code quality issues. When it is determined that the access inspection has failed, identify the code quality issues in the code files in the pipeline based on the code inspection tasks whose inspection results do not meet the corresponding preset thresholds, edit and read and write the code files, modify the code of the code files according to the repair specifications for the code quality issues, form a modified code file, and build a repaired pipeline based on the modified code file.

[0144] In some possible implementations, after the code of the code file is modified according to the repair specifications of the code quality problems to form a modified code file, the code inspection tasks whose inspection results do not meet the preset threshold, the code quality problems existing in the code file, and the modified code file are sent to the development / tester, and in response to the repair confirmation operation input by the development / tester, a repaired pipeline is built based on the modified code file.

[0145] In some other possible implementations, after the code of the code file is modified according to the repair specifications of the code quality problems to form a modified code file, the code inspection tasks whose inspection results do not meet the preset threshold, the code quality problems existing in the code file, and the modified code file are sent to the development / tester, and in response to the modification operations input by the development / tester, the repaired code file is modified to form a new code file, the new code file is used as the repaired code file, and the repaired pipeline is constructed based on the modified code file.

[0146] In some other embodiments, when it is determined that the access check fails, the updated pipeline can be stopped, and new inspection results of the code inspection tasks that need to be access checked in the access check set in the target access rules are obtained at preset intervals, and the new inspection results of the code inspection tasks that need to be access checked are re-access checked. When the new inspection results of each code inspection task meet the preset thresholds corresponding to each code inspection task, it is determined that the access check has passed. When there is at least one code inspection task whose new inspection result does not meet the preset threshold corresponding to the code inspection task, it is determined that the access check has failed. This is repeated until the access check passes, and the updated pipeline continues to be executed.

[0147] The pipeline operation method provided in the embodiment of the present application pre-configures access rules, and when a deployment task including access rule settings is identified in the pipeline, the task is deployed in the pipeline to generate an access node, and the code inspection task of the deployment task is verified. In this way, there is no need to deploy inspection tools on each pipeline, and by dynamically generating access nodes, the risk of missing configurations and bypassing of access interception can be avoided.

[0148] In one possible implementation, in step S210, in order to quickly and accurately obtain the target access rules corresponding to the pipeline to be deployed and improve the pipeline operation efficiency, it is necessary to configure the access rules before the pipeline runs, or before step S210, to form pre-configured access rules, and configure the application scope corresponding to each pre-configured access rule. In this way, in step S210, after determining the pipeline to be deployed, the target application scope of the pipeline to be deployed is determined, and according to the application scope corresponding to the pre-configured access rules, the access rules corresponding to the target application scope among multiple pre-configured access rules are determined as target access rules. In this way, according to the application scope, the target access rules corresponding to the pipeline to be deployed can be quickly and accurately identified, thereby improving the pipeline operation efficiency and realizing the automatic generation of access nodes in the pipeline.

[0149] The configuration of the access rules can refer to the above-mentioned embodiment in which the administrator inputs the access rule configuration operation through the access rule configuration function control, and Figure 7 Provided access rule configuration examples, or refer to Fig.12 Steps S121 to S122 in the provided method for establishing an association relationship between access rules and pipeline sets are not described in detail in the embodiment of the present application.

[0150] Among them, the application scope is used to divide the pipeline, and the application scope corresponding to the access rule is used to determine the pipeline to which the access rule can be applied. For example, taking the target application scope of the pipeline to be deployed as range A, when the application scope of the preconfigured access rule 1 is range S, the application scope of the preconfigured access rule 2 is range U, the application scope of the preconfigured access rule 3 is range J, and the application scope of the preconfigured access rule 4 is range A, then the preconfigured access rule 4 is determined as the target application rule corresponding to the pipeline to be deployed.

[0151] It is understandable that if there is no access rule corresponding to the target application scope among multiple pre-configured access rules, it means that the target application scope where the pipeline to be deployed is located has no access rule set, then the pipeline to be deployed will be run directly, that is, the access node will not be deployed in the pipeline, and access interception will not be performed.

[0152] The target application scope may be determined according to the category of the pipeline to be deployed, or according to the application service corresponding to the pipeline to be deployed, or according to the department information where the pipeline to be deployed is located.

[0153] Exemplarily, taking the example of determining the target application scope according to the category of the pipeline to be deployed, according to the pipeline information to be deployed, the pipeline information includes the category of the pipeline to be deployed, and according to the category of the pipeline, the mapping relationship between the category and the application scope is queried to obtain the target application scope corresponding to the pipeline. Among them, the mapping relationship between the category and the application scope is used to indicate the mapping relationship between the category of the pipeline and the corresponding application scope. For example, the application scopes corresponding to category 1 and category 2 are both range A, and the application scope corresponding to category 3 is range B. When the category of the pipeline to be deployed is category 3, range B is determined as the target application scope.

[0154] Exemplarily, taking the example of determining the target application scope according to the application service corresponding to the pipeline to be deployed, based on the pipeline information to be deployed, the pipeline information includes the application service of the pipeline to be deployed, and the application service of the pipeline, or the type of the application service, is used as the target application scope.

[0155] Exemplarily, taking determining the target application scope according to the department information of the assembly line to be deployed as an example, according to the assembly line information to be deployed, the assembly line information includes the department information of the assembly line, and the department information of the assembly line is determined as the target application scope.

[0156] In another possible implementation, in step S210, in order to quickly and accurately obtain the target access rules corresponding to the pipeline to be deployed and improve the pipeline operation efficiency, it is necessary to configure the access rules before the pipeline is run, or before step S210, to form pre-configured access rules, and configure the application services corresponding to each pre-configured access rule. In this way, in step S210, after determining the pipeline to be deployed, the target application service of the pipeline to be deployed is determined, and according to the application service corresponding to the pre-configured access rules, the access rules corresponding to the target application service among multiple pre-configured access rules are determined as the target access rules. In this way, according to the application service, the target access rules corresponding to the pipeline to be deployed can be quickly and accurately identified, thereby improving the pipeline operation efficiency and realizing the automatic generation of access nodes in the pipeline.

[0157] In another possible implementation, in step S210, in order to quickly and accurately obtain the target access rules corresponding to the pipeline to be deployed and improve the pipeline operation efficiency, it is necessary to configure the access rules before the pipeline is run, or before step S210, to form pre-configured access rules, and configure the pipeline set corresponding to each pre-configured access rule to form an association relationship between the pre-configured access rules and the pipeline set, so that in step S210, after determining the pipeline to be deployed, the pipeline set where the pipeline to be deployed is located is determined, and according to the association relationship between the pre-configured access rules and the pipeline set, the access rules corresponding to the pipeline set to be deployed are determined as the target access rules. In this way, according to the pipeline set, the target access rules corresponding to the pipeline to be deployed can be quickly and accurately identified, and the automatic generation of access nodes in the pipeline can be realized while improving the pipeline operation efficiency.

[0158] The association relationship between the pre-configured admission rules and the pipeline set is used to indicate the mapping relationship between the pipeline set and the corresponding admission rules.

[0159] Among them, pipeline sets can be divided according to the category of pipelines, for example, pipelines of the same category are grouped into one pipeline set. Pipeline sets can also be divided according to the application services corresponding to the pipelines, for example, pipelines with the same or similar application services are grouped into one pipeline set. Pipeline sets can also be divided according to the department information of the pipelines, for example, pipelines with the same department information are grouped into the same pipeline set. Pipeline sets can also be divided according to the creation time of the pipelines, for example, pipelines with creation time within the same time range are grouped into the same pipeline set.

[0160] It is understandable that after determining the pipelines to be deployed, the set of pipelines to be deployed can be determined based on one or more of the categories of the pipelines, the corresponding application services, the department information, and the creation time.

[0161] The association relationship between the preconfigured access rules and the pipeline set can be obtained by selecting an access rule from preset access rule data in response to an access rule selection operation, and associating the selected access rule with the selected pipeline set. The preset access rule data includes multiple preconfigured access rules.

[0162] The association relationship between the preconfigured admission rules and the pipeline set may also be obtained by receiving preconfigured admission rules sent from other devices and associating the received admission rules with the selected pipeline set.

[0163] The association relationship between the pre-configured admission rules and the pipeline set may also be obtained by configuring the admission rules in response to an admission rule configuration operation, and associating the configured admission rules with the selected pipelines in a set.

[0164] As an example and not a limitation, in the case where the association relationship between the preconfigured admission rules and the pipeline set is obtained by configuring the admission rules in response to the admission rule configuration operation, and associating the configured admission rules with the selected pipelines in a set, such as Fig.12 As shown, Fig.12 1 is a flow chart of a method for establishing an association relationship between an access rule and a pipeline set provided in an embodiment of the present application. The method for establishing an association relationship between an access rule and a pipeline set shown includes steps S121 to S124:

[0165] Step S121, in response to the access rule configuration operation, displaying a configuration page view.

[0166] In a possible implementation, the interface view of the pipeline system is as described above. Figure 5 As shown, you can refer to the above Figure 7 The provided embodiment, in response to the access rule configuration operation, displays a configuration page view and an environment tag of the deployment task input based on the configuration page view, an environment tag of the code checking task corresponding to the deployment task, and a preset threshold of the code checking task, to form a preconfigured access rule. The embodiments of the present application are not described in detail here.

[0167] In another possible implementation, the pipeline system is provided with an access rule configuration center, and a function control for entering the access rule configuration center is provided in the interface view of the pipeline system, such as Fig.13 As shown in (a) of FIG; the pipeline system responds to the click operation of the function control of entering the access rule configuration center, and displays the page view of the access rule configuration center in the interface view, such as Fig.13 As shown in FIG. 1( b), a function control for inputting access rule configuration operations is provided in the page view of the access rule configuration center. The pipeline system responds to the access rule configuration operations inputted based on the function control for inputting the access rule configuration operations, and displays the configuration page view, such as Fig.13 As shown in Figure (c), the configuration page view is provided with a text input box for the access rule name, text input boxes for the environment labels of multiple deployment tasks, an access rule configuration confirmation control and a cancel control, and the text input box for the environment label of each deployment task is also provided with a text input box for the environment label of the code checking task, and a threshold setting control.

[0168] The interface view of the pipeline system is provided with an access rule configuration area, a pipeline construction area, and a pipeline operation area. The access rule configuration area is provided with an access rule configuration startup control. In response to the access rule configuration operation input based on the access rule configuration startup control, the following is displayed: Fig.13 The configuration page view shown in Figure (a) in the figure.

[0169] Considering that in the prior art, developers, testers, and managers can edit pipelines, deploy code checking tools and access control in the pipelines, there is a risk of code checking interception bypass when the deployment task is arranged before the code checking tool. Based on this, in some implementations, in order to reduce the risk of code checking interception bypass and prevent multiple roles from editing the pipeline, permission verification is provided when configuring access rules, and permission verification is used to prevent multiple roles from editing the pipeline, thereby improving the reliability of access rules.

[0170] Exemplarily, in response to the access rule configuration operation, the permission verification view is output, the verification information input based on the permission verification view is obtained, and the permission verification is performed based on the verification information. When the permission verification passes, the configuration page view is displayed, and when the permission verification fails, the configuration interface view is not displayed, and prompt information is output in the current interface view, such as the prompt information of "exceeding authority" or "please re-verify". The verification information can be a pre-set password, or it can be the facial information, work number identification or fingerprint information of the person who inputs the access rule configuration operation.

[0171] Step S122, forming a preconfigured access rule based on the environment tag of the deployment task input in the configuration page view, the environment tag of the code checking task corresponding to the deployment task, and the preset threshold of the code checking task.

[0172] In a possible implementation, in response to a click operation on the text input box of the environment tag of the deployment task, the environment tags of the deployment tasks that can perform access checks are displayed in the form of a drop-down list. In response to a selection operation on the environment tag in the drop-down list view, the selected environment tag is filled into the text input box of the environment tag of the deployment task. In response to a click operation on the text input box of the environment tag of the code check task in the text input box of the environment tag of the deployment task, the environment tags of the code check task that performs access checks are displayed in the form of a drop-down list. In response to a selection operation on the environment tag in the drop-down page table view, the selected environment tag is filled into the text input box of the environment tag of the code check task. In response to a click operation on the threshold setting control, the threshold setting page view is displayed in the current page view, and the threshold setting box of the code check task filled in the text input box of the environment tag of the code check task and the threshold confirmation control are displayed in the threshold setting page view.

[0173] After entering the preset threshold of the code inspection task through the threshold setting box, click the threshold confirmation control to complete the threshold setting of the code inspection task, cache the preset threshold of the code inspection task under the environment tag of the deployment task, and close the threshold setting page view.

[0174] For example, in response to a click operation on the access rule configuration confirmation control in the configuration page view, a preconfigured access rule is formed based on the data content in the text input box of the environment tag of the deployment task in the configuration page view, the data content in the text input box of the environment tag of the deployment task, the data content in the text input box of the environment tag of the code checking task, and the preset threshold of the code checking task.

[0175] Step S123, displaying at least one pipeline set information in the configuration page view, and in response to a selection operation based on the pipeline set information input, obtaining a pipeline set corresponding to the pre-configured access rule.

[0176] In some embodiments, a pipeline set selection control is also provided in the configuration page view. In response to a click operation on the pipeline set selection control, at least one pipeline set information is displayed in the configuration page view. In response to a selection operation based on the pipeline set information input, a pipeline set corresponding to a preconfigured access rule is obtained.

[0177] In some other embodiments, in response to a click operation on an access rule configuration confirmation control in a configuration page view, a preconfigured access rule is formed based on the data content in the text input box of the environment tag of the deployment task in the configuration page view, the data content in the text input box of the environment tag of the deployment task, the data content in the text input box of the environment tag of the code checking task, and a preset threshold of the code checking task, and a pipeline set selection operation is triggered, at least one pipeline set information is displayed in the configuration page view, and in response to a selection operation based on the pipeline set information input, a pipeline set corresponding to the preconfigured access rule is obtained.

[0178] Step S124, associating the preconfigured admission rule with the pipeline set corresponding to the preconfigured admission rule, and obtaining an association relationship between the preconfigured admission rule and the pipeline set.

[0179] based on Fig.12 The provided embodiment forms access rules by inputting environment tags of deployment tasks and environment tags of code checking tasks through the configuration page view, and associates the selected pipeline set with the access rules to form an association relationship between the pre-configured access rules and the pipeline set, thereby achieving flexibility and applicability of access rule configuration; at the same time, through permission verification, it is prevented that multiple roles can edit the pipeline, thereby improving the reliability of the access rules.

[0180] In some embodiments, after configuring the access rules, the preconfigured access rules are saved. After determining the pipeline to be deployed, the target access rules corresponding to the pipeline to be deployed are determined according to the target application scope of the pipeline to be deployed or the pipeline set. After determining the target access rules corresponding to the pipeline to be deployed, it is possible to follow the above-mentioned step S220 to determine whether the pipeline to be deployed includes the deployment tasks specified by the target access rules according to the environment tags of the deployment tasks specified in the target access rules and the environment tags of the deployment tasks in the pipeline to be deployed. If the pipeline to be deployed includes the deployment tasks specified by the target access rules, an access node corresponding to the deployment task is generated in the pipeline to obtain an updated pipeline.

[0181] Among them, when a deployment task with an environment label is specified in the target entry, when the pipeline to be deployed includes the deployment task specified by the target entry rule, before the deployment task in the pipeline to be deployed whose environment label is consistent with the environment label of the deployment task specified by the target entry rule, an access node corresponding to the deployment task is generated to form an updated pipeline.

[0182] Among them, in the case where multiple deployment tasks with different environmental labels are specified in the target access rule, when the pipeline to be deployed includes at least one deployment task specified by the target access rule, before each deployment task in the pipeline to be deployed whose environmental label is consistent with the environmental label of the deployment task specified by the target access rule, an access node corresponding to the deployment task is generated to form an updated pipeline.

[0183] It is understandable that, in the case where multiple deployment tasks with different environment labels are specified in the target entry rules, when the pipeline to be deployed includes at least one deployment task specified by the target entry rules, the updated pipeline is deployed with an access node corresponding to at least one deployment task, and each deployment task corresponds to a different environment label.

[0184] For example, a target entry rule specifies a deployment task with multiple environment tags. For example, the deployment task specified in the target entry rule includes: a deployment task for the Beta environment, a deployment task for the Gamma environment, and a deployment task for the Prod environment. Fig.14 As shown in Figure (a), the pipeline to be deployed includes the deployment tasks of the Alpha environment, the Beta environment, the Gamma environment, and the Prod environment in sequence. Then, admission nodes are generated before the deployment tasks of the Beta environment, the Gamma environment, and the Prod environment of the pipeline to be deployed, respectively, as follows: Fig.14As shown in Figure (b), in the admission node corresponding to each deployment task, based on the inspection results of the code inspection tasks corresponding to the deployment tasks before each deployment task, the code inspection tasks that enter the admission inspection in the target admission rules are inspected. Fig.14 As shown in Figure (b), in the admission node corresponding to the deployment task of the Beta environment, an admission check is performed on the inspection results of the cloud test of the Alpha environment and the inspection results of the variable scan of the Alpha environment; in the admission node corresponding to the deployment task of the Gamma environment, an admission check is performed on the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scan of the Alpha environment, the inspection results of the cloud test of the Beta environment, and the inspection results of the variable scan of the Beta environment; in the admission node corresponding to the deployment task of the Prod environment, an admission check is performed on the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scan of the Alpha environment, the inspection results of the cloud test of the Beta environment, the inspection results of the variable scan of the Beta environment, the inspection results of the cloud test of the Gamma environment, and the inspection results of the variable scan of the Gamma environment.

[0185] In one possible implementation, when the updated pipeline is running, the verification node pushes the inspection results of the code inspection task before the deployment task to the admission node corresponding to the deployment task. When the admission node performs the admission check, it obtains the inspection results of the code inspection task pushed by the verification node deployed by the updated pipeline.

[0186] Among them, the deployment task of each stage in the pipeline is deployed with a code inspection task and a verification node corresponding to the code inspection task. The verification node executes the code inspection task and obtains the inspection result of the code inspection task. Fig.14 As shown in Figure (a), a verification node is deployed between the deployment task of the Alpha environment and the deployment task of the Beta environment. The verification node performs code checking of the cloud test task of the Alpha environment and code checking of the variable scanning task of the Alpha environment.

[0187] For example, Fig.14 As shown in Figure (b), verification node 1 pushes the inspection results of the cloud test task of the Alpha environment and the inspection results of the variable scanning task of the Alpha environment to the admission node corresponding to the deployment task of the Beta environment.

[0188] If the access check fails, the pipeline will be re-run. Fig.14As shown in Figure (b), if the access check of the deployment task of the Beta environment fails, the updated pipeline will be re-run to re-execute the deployment task of the Alpha environment, and verification node 1 will execute the code checking task in the Alpha environment; if the access check of the deployment task of the Prod environment fails, the updated pipeline will be re-run to re-execute the deployment task of the Alpha environment, verification node 1 will execute the code checking task in the Alpha environment, the access node will execute the access check of the deployment task of the Beta environment, the deployment task of the Beta environment, verification node 2 will execute the code checking task in the Beta environment, the access node will execute the access check of the deployment task of the Gamma environment, verification node 3 will execute the code checking task in the Gamma environment, and the access node will execute the access check of the deployment task of the Prod environment.

[0189] Considering that the verification node in the pipeline only applies the inspection task of the code inspection task to the access node deployed on the pipeline, when the access check fails, the pipeline will be re-run. When more tasks are executed in the pipeline, the running time cost of the pipeline will increase, and the inspection result of the code inspection task of the same code file is idempotent, that is, the inspection result of executing multiple code inspection tasks and executing one code inspection task on the same code file is the same. Therefore, in some embodiments, when the software package is deployed through the CICD pipeline, the inspection result of the code inspection task of the software package at each stage is pushed (that is, stored) to the indicator lake. When the pipeline runs to the access node, the inspection result of the code inspection task is pulled from the indicator lake and the access check is performed. In this way, the cross-pipeline application of the code inspection task is realized, and when the access check fails, it is only necessary to re-run the sub-pipeline where the code inspection result that does not meet the preset threshold is located, and there is no need to re-run the entire pipeline, thereby improving the running efficiency of the pipeline. In some possible implementations, the pipeline is divided into multiple sub-pipelines, each sub-pipeline corresponds to at least one deployment task, each deployment task corresponds to a different environment label, and each sub-pipeline is run to obtain the inspection results of the code inspection tasks in the deployment tasks under different environment labels, and the inspection results of the code inspection tasks in the deployment tasks under different environment labels are saved in the indicator lake. When the updated pipeline is running, when it runs to the access node corresponding to the deployment task, the inspection results of the code inspection tasks corresponding to the deployment tasks in the updated pipeline are obtained from the indicator lake.

[0190] For example, the pipeline may be divided into a plurality of sub-pipelines according to the stage where the execution task in the pipeline is located, and each pipeline includes the execution task of at least one stage.

[0191] Exemplarily, the execution tasks of the development phase are divided into one sub-pipeline, the execution tasks of the test phase are divided into one sub-pipeline, the execution tasks of the verification phase are divided into one sub-pipeline, and the execution tasks of the production phase are divided into one sub-pipeline. Among them, the execution tasks of the development phase include the deployment tasks of the development environment and the verification tasks of the development environment, the execution tasks of the test phase include the deployment tasks of the test environment and the verification tasks of the test environment. The execution tasks of the verification phase include the deployment tasks of the verification test environment and the verification tasks of the verification test environment, and the execution tasks of the production phase include the deployment tasks of the production environment.

[0192] For example, the pipeline may be divided into a plurality of sub-pipelines according to the environment tags of the execution tasks in the pipeline, and each sub-pipeline includes execution tasks with at least one environment tag.

[0193] For example, Fig.14 Taking the pipeline shown in Figure (a) as an example, the deployment tasks of the Alpha environment and the verification tasks in the Alpha environment can be divided into sub-pipeline 1, the deployment tasks of the Beta environment and the verification tasks in the Beta environment can be divided into sub-pipeline 2, the verification tasks of the Gamma environment and the verification tasks in the Gamma environment can be divided into sub-pipeline 3, and the deployment tasks of the Prod environment can be divided into sub-pipeline 4. Fig.15 As shown, Fig.14 The pipeline shown in Figure (a) is divided into four sub-pipelines.

[0194] When the inspection results of the code inspection tasks in the deployment tasks under different environment tags are saved in the indicator lake, the environment tag of the deployment task in the sub-pipeline, the inspection results of the code inspection tasks in the deployment tasks under the environment tag, and the identification information of the software package corresponding to the deployment task under the environment tag can be saved in the indicator lake for each sub-pipeline. For example, the environment tag of the deployment task in the sub-pipeline, the identification information of the software package corresponding to the deployment task under the environment tag, and the task identification of the code inspection task in the deployment task under the environment tag are used as indexes, and the inspection results of the code inspection tasks are used as data corresponding to the indexes and saved in the indicator lake.

[0195] For example, the identification information of the software package of the sub-pipeline, the task identification of the code inspection task, and the environment tag of the code inspection task can be used as the index, and the inspection result of the code inspection task can be used as the data corresponding to the index and saved to the indicator lake. For example, taking the identification information of the software package as Package_A as an example, the index in the indicator lake is Package_AAlpha cloud test data, which represents the inspection result of the cloud test task of the software package Package_A in the Alpha environment.

[0196] Correspondingly, when the code inspection results of the sub-pipeline are stored in the indicator lake, when the updated pipeline is run, the admission node uses the environment label, task identifier, and software package identification information corresponding to the code inspection task in the updated pipeline as the index, and queries the indicator lake to obtain the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline. For example, when the environment label of the code inspection task in the updated pipeline is Alpha, the task identifier is cloud test, and the software package identification information is Package_A, the data indexed as Package_AAlpha cloud test in the indicator lake is used as the inspection result of the code inspection task.

[0197] For example, the identification information of the software package is Package_A, and the deployment task specified in the target entry rule is the deployment task of the Prod environment. Fig.16 As shown, an access node is generated before the deployment task of the Prod environment in sub-pipeline 4; sub-pipeline 1, sub-pipeline 2, and sub-pipeline 3 respectively execute the deployment task and verification task of the software package Package_A in the Alpha environment, the deployment task and verification task of the Beta environment, and the deployment task and verification task of the Gamma environment, and push the inspection results of the code inspection task of the Alpha environment, the inspection results of the code inspection task of the Beta environment, and the inspection results of the code inspection task of the Gamma environment to the indicator lake, in which the identification information of the software package, the environment label of the code inspection task, and the task identification are used as indexes, and the inspection results of the code inspection task are stored as data; sub-pipeline 4 is an updated pipeline. When it runs to the access node, it forms an index according to the identification information of the software package, the task identification and environment label of the code inspection task for access inspection specified in the target entry rule, and obtains the inspection result of the code inspection task for access inspection from the indicator lake, as shown in FIG. Fig.16 As shown, the inspection results of the cloud test of the Alpha environment, the inspection results of the variable scan of the Alpha environment, the inspection results of the cloud test of the Beta environment, the inspection results of the variable scan of the Beta environment, the inspection results of the cloud test of the Gamma environment, and the inspection results of the variable scan of the Gamma environment are obtained from the indicator lake.

[0198] Wherein, in the case where the inspection results of the code inspection tasks in the sub-pipeline are saved through the indicator lake, the inspection results of the code inspection tasks saved in the indicator lake can be applied to the access inspection of the deployment tasks in the first pipeline, wherein the first pipeline is any pipeline that includes the deployment tasks specified by the target entry rules. Exemplarily, taking the deployment tasks specified by the target entry rules as the deployment tasks of the Prod environment as an example, when the first pipeline is executed to the access node corresponding to the deployment tasks of the Prod environment, the indicator lake is queried to obtain the inspection results of the code inspection tasks for the access inspection of the software package of the first pipeline specified by the target entry rules from the indicator lake.

[0199] In one possible implementation, when querying the indicator lake to obtain the inspection result of the code inspection task, if the index of the inspection result of the code inspection task exists in the indicator lake, the data corresponding to the index in the indicator lake is used as the inspection result of the code inspection task; if the index of the inspection result of the code inspection task does not exist in the indicator lake, the operation of the updated pipeline continues to be stopped, and according to a preset period, the indicator lake is queried again with the identification information of the software package of the updated pipeline, the environment label of the code inspection task for access check specified by the target access rule, and the identification information of the software package as indexes to obtain the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline, until the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline is obtained, and the access check is performed.

[0200] Among them, when the inspection results of the code inspection tasks in the sub-pipeline are saved through the indicator lake, when the access node performs an access check on the inspection results of the code inspection tasks corresponding to the deployment tasks in the updated pipeline, if the access check passes, the deployment task is executed and the updated pipeline continues to run. If the access check fails, the inspection results of the code inspection tasks corresponding to the deployment tasks are output. According to the preset cycle, the indicator lake is queried with the identification information of the software package of the updated pipeline and the environment label of the code inspection task for access check corresponding to the target entry rule as the index to obtain the new inspection result of the code inspection task corresponding to the deployment task in the updated pipeline, and whether the access check is passed is determined according to the new inspection result of the code inspection task corresponding to the deployment task.

[0201] Among them, when outputting the inspection results of the code inspection tasks, the inspection results of the code inspection tasks for access inspection specified in the target access rules can be output; or the code inspection tasks for access inspection specified in the target access rules, whose inspection results do not meet the corresponding preset thresholds and the corresponding inspection results can be output.

[0202] For example, the inspection results of the code inspection task can be displayed in the interface view of the pipeline system, or the inspection results of the code inspection task can be pushed to the development / tester by email, text message, etc., so that the development / tester can repair the sub-pipeline according to the inspection results of the code inspection task and re-run the repaired sub-pipeline. When the sub-pipeline is re-run, the new inspection results of the code inspection task in the sub-pipeline are pushed to the indicator lake, and the inspection results of the code inspection task in the sub-pipeline in the indicator lake are updated.

[0203] Among them, the repair of the sub-pipeline can refer to the repair method of the pipeline to be deployed provided in the above step S230, or refer to the automatic repair of the sub-pipeline based on the inspection result in the above step S230, which is not repeated in the embodiments of the present application.

[0204] An implementation scheme for obtaining inspection results of code inspection tasks based on an indicator lake realizes cross-pipeline application of inspection results of code inspection tasks through the indicator lake. When the access inspection fails, only the sub-pipeline where the code inspection results that do not meet the preset threshold are located needs to be re-run, without the need to re-run the entire pipeline, thereby improving the operation efficiency of the pipeline.

[0205] In order to better implement the method for running the pipeline provided in the embodiment of the present application, a device for running the pipeline is provided based on the embodiment of the method for running the pipeline, such as Fig.17 As shown, Fig.17 1 is a schematic diagram of the structure of the device 17 for running the pipeline provided in an embodiment of the present application, and the device 17 for running the pipeline shown includes:

[0206] The acquisition module 171 is used to acquire the target access rule corresponding to the pipeline to be deployed from the pre-configured access rules; wherein the pre-configured access rule is used to specify the deployment task for access check and the code check task corresponding to the deployment task; the pipeline includes at least one deployment task;

[0207] A deployment module 172, configured to generate an access node corresponding to the deployment task in the pipeline when the pipeline to be deployed includes the deployment task specified by the target entry rule, so as to obtain an updated pipeline; wherein the access node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task;

[0208] The running module 173 is used to run the updated pipeline.

[0209] Among them, the acquisition module 171, the deployment module 172, and the operation module 173 can all be implemented by software or by hardware. Exemplarily, the implementation of the acquisition module 171 is described below by taking the acquisition module 171 as an example. Similarly, the implementation of the deployment module 172 and the operation module 173 can refer to the implementation of the acquisition module 171.

[0210] As an example of a software functional unit, the acquisition module 171 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the acquisition module 171 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region (region) or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Among them, usually a region may include multiple AZs.

[0211] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.

[0212] As an example of a hardware functional unit, the acquisition module 171 may include at least one computing device, such as a server, etc. Alternatively, the acquisition module 171 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.

[0213] The multiple computing devices included in the acquisition module 171 can be distributed in the same region or in different regions. The multiple computing devices included in the A module can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the acquisition module 171 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0214] It should be noted that the naming and grouping of the devices and modules in the embodiments of the present application are schematic and are only a logical function grouping. In actual implementation, there may be other grouping methods. For example, the running pipeline device 17 may also be named as a quality release module or other names without limitation.

[0215] It should be noted that, in other embodiments, the acquisition module 171 can be used to execute any step in the method of running the pipeline, the deployment module 172 can be used to execute any step in the method of running the pipeline, and the operation module 173 can be used to execute any step in the method of running the pipeline. The steps that the acquisition module 171, the deployment module 172, and the operation module 173 are responsible for implementing can be specified as needed. The acquisition module 171, the deployment module 172, and the operation module 173 respectively implement different steps in the method of running the pipeline to realize all the functions of the device for running the pipeline.

[0216] The embodiment of the present application also provides a computing device cluster for executing the above-mentioned method of running the pipeline.

[0217] In one example, a computing device cluster may include: Fig.17 The device 17 for running the pipeline shown includes an acquisition module 171 , a deployment module 172 and an operation module 173 .

[0218] In another example, the computing device cluster includes at least one computing device, and the computing device may include: Fig.17 The apparatus 17 for running the pipeline shown includes an acquisition module 171, a deployment module 172, and an operation module 173. In one possible implementation, the computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In another possible implementation, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0219] In one example, the computing device cluster includes at least one computing device, such as Fig.18As shown, the computing device 18 includes: a bus 182, a processor 184, a memory 186, and a communication interface 188. The processor 184, the memory 186, and the communication interface 188 communicate with each other through the bus 182. The computing device 18 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors 184 and memories 186 in the computing device 18.

[0220] The bus 182 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.18 The bus 182 may include a path for transmitting information between various components of the computing device 18 (eg, the memory 186, the processor 184, and the communication interface 188).

[0221] The processor 184 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0222] The memory 186 may include a volatile memory, such as a random access memory (RAM). The processor 184 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0223] The memory 186 stores executable program codes, and the processor 184 executes the executable program codes to respectively implement the functions of the acquisition module 171, the deployment module 172, and the operation module 173, thereby implementing the method for running the pipeline. That is, the memory 186 stores instructions for executing the method for running the pipeline.

[0224] The communication interface 188 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 18 and other devices or a communication network.

[0225] The method for running the pipeline disclosed in the above method embodiment may be applied to the processor 184, or implemented by the processor 184. The processor 184 may be an integrated circuit chip having signal processor capabilities.

[0226] In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 184. The above processor 184 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete electron tubes or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to be executed, or the hardware and software modules in the decoding processor can be combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 186, and the processor 184 reads the information in the memory 186 and completes the steps of the above method in combination with its hardware.

[0227] In a possible implementation, the processor 184 may also be used to execute a pipeline operation method. For a specific implementation, reference may be made to the embodiments provided in the above-mentioned pipeline operation method, and the embodiments of the present application will not be described in detail herein.

[0228] In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.

[0229] The embodiment of the present application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be completed by a computer program to instruct the relevant hardware, and the program can be stored in the above computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be a terminal of any of the above embodiments, such as: an internal storage unit including a data transmission end and / or a data receiving end, such as a hard disk or memory of a terminal. The above computer-readable storage medium can also be an external storage device of the above terminal, such as a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (securedigital, SD) card, a flash card (flash card), etc. equipped on the above terminal. Further, the above computer-readable storage medium can also include both the internal storage unit of the above terminal and an external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above terminal. The above computer-readable storage medium can also be used to temporarily store data that has been output or is to be output.

[0230] It should be understood that the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the technical solution of this application are in compliance with relevant laws and regulations and do not violate public order and good morals. For example, in the technical solution of this application, the processing of user personal information is carried out with the authorization of the user, and the same description is not repeated here.

[0231] It should be noted that the terms "first" and "second" in the specification, claims and drawings of the present application are used to distinguish different objects rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or devices.

[0232] It should be understood that in the present application, "at least one (item)" means one or more, "more than one" means two or more, "at least two (items)" means two or three and more than three, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0233] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined based on A. It should also be understood that determining B based on A does not mean determining B only based on A, but B can also be determined based on A and / or other information. In addition, the "connection" that appears in the embodiments of the present application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and the embodiments of the present application do not impose any limitation on this.

[0234] Unless otherwise specified, the "transmission" (transmit / transmission) appearing in the embodiments of the present application refers to bidirectional transmission, including sending and / or receiving actions. Specifically, the "transmission" in the embodiments of the present application includes the sending of data, the receiving of data, or the sending of data and the receiving of data. In other words, the data transmission here includes uplink and / or downlink data transmission. Data may include channels and / or signals, uplink data transmission is uplink channel and / or uplink signal transmission, and downlink data transmission is downlink channel and / or downlink signal transmission. The "network" and "system" appearing in the embodiments of the present application express the same concept, and an all-optical network is an all-optical system.

[0235] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the grouping of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be grouped into different functional modules to complete all or part of the functions described above.

[0236] In the several embodiments provided in the present application, it should be understood that the disclosed communication devices and methods can be implemented in other ways. For example, the communication device embodiments described above are only schematic. For example, the grouping of the modules or units is only a logical function grouping. There may be other grouping methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0237] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0238] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0239] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device, such as a single-chip microcomputer, a chip, etc., or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media for storing program codes such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks or optical disks.

[0240] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method of running a pipeline, It is characterized in that include: Obtaining a target access rule corresponding to the pipeline to be deployed from preconfigured access rules; wherein the preconfigured access rule is used to specify a deployment task for access check and a code check task corresponding to the deployment task; the pipeline includes at least one deployment task; In the case where the pipeline to be deployed includes a deployment task specified by the target entry rule, an access node corresponding to the deployment task is generated in the pipeline to obtain an updated pipeline; wherein the access node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task; Run the updated pipeline.

2. The method according to claim 1, It is characterized in that The preconfigured admission rule includes: an environment tag of a deployment task that enters the admission check, and an environment tag of a code check task corresponding to the deployment task.

3. The method according to claim 1 or 2, It is characterized in that The preconfigured access rule also includes at least one preset threshold; the preset threshold is set with an environment label, and the preset threshold is used to check whether the inspection result of the code inspection task corresponding to the environment label in the pipeline meets the access rule.

4. The method according to claim 1, It is characterized in that The preconfigured admission rules include multiple ones, and different preconfigured admission rules correspond to different application scopes; the step of obtaining the target admission rule corresponding to the pipeline to be deployed from the preconfigured admission rules includes: Determine the target application scope of the pipeline to be deployed; The access rule corresponding to the target application scope among the multiple pre-configured access rules is determined as the target access rule.

5. The method according to claim 1, It is characterized in that The step of obtaining the target admission rule corresponding to the pipeline to be deployed from the pre-configured admission rules includes: Based on the association relationship between the preconfigured access rules and the pipeline set, the access rules corresponding to the pipeline set to be deployed are determined as the target access rules; the association relationship between the preconfigured access rules and the pipeline set is used to indicate the mapping relationship between the pipeline set and the corresponding access rules.

6. The method according to claim 5, It is characterized in that Before acquiring the target admission rule corresponding to the pipeline to be deployed from the preconfigured admission rules, the method further includes: The association relationship between the preconfigured admission rules and the pipeline set is obtained by associating the admission rules configured in response to the admission rule configuration operation with the selected pipeline set.

7. The method according to claim 6, It is characterized in that The method further comprises: In response to the access rule configuration operation, displaying a configuration page view; Based on the environment tag of the deployment task input in the configuration page view, the environment tag of the code checking task corresponding to the deployment task, and the preset threshold of the code checking task, a preconfigured access rule is formed; Displaying at least one pipeline set information in the configuration page view, and acquiring the pipeline set corresponding to the preconfigured admission rule in response to a selection operation input based on the pipeline set information; The preconfigured admission rule is associated with the pipeline set corresponding to the preconfigured admission rule to obtain an association relationship between the preconfigured admission rule and the pipeline set.

8. The method according to any one of claims 1 to 7, It is characterized in that The running of the updated pipeline comprises: Obtaining the inspection result of the code inspection task corresponding to the deployment task; Determine whether the access check is passed according to the inspection result of the code inspection task corresponding to the deployment task; If the access check passes, the deployment task is executed and the updated pipeline continues to run; If the access check fails, the deployment task is not executed and the updated pipeline is stopped.

9. The method according to claim 8, It is characterized in that The determining whether the access check is passed according to the check result of the code check task corresponding to the deployment task includes: If the inspection results of all code inspection tasks corresponding to the deployment task meet the preset threshold corresponding to the code inspection task environment tag, the access inspection passes; If the inspection result of at least one of the code inspection tasks does not meet the preset threshold, the access inspection fails.

10. The method according to claim 8, It is characterized in that The pipeline is deployed with a code inspection task and a verification node corresponding to the code inspection task; the obtaining the inspection result of the code inspection task corresponding to the deployed task includes: The admission node obtains the inspection result of the code inspection task corresponding to the deployment task pushed by the verification node.

11. The method according to claim 10, It is characterized in that At least one access interception point corresponding to a deployment task is deployed in the updated pipeline, and each deployment task corresponds to a different environment label; The access interception point corresponding to each of the deployment tasks is used to perform access checks on each of the code inspection tasks based on the inspection results of the code inspection tasks corresponding to the deployment tasks before each of the deployment tasks.

12. The method according to claim 8, It is characterized in that The pipeline includes multiple sub-pipelines, each of the sub-pipelines corresponds to at least one deployment task, and each of the deployment tasks corresponds to a different environment tag; Run each of the sub-pipelines to obtain inspection results of the code inspection tasks in the deployment tasks under different environment tags, and save the inspection results of the code inspection tasks in the deployment tasks under the different environment tags into the indicator lake; The obtaining the inspection result of the code inspection task corresponding to the deployment task includes: Obtain from the indicator lake the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline.

13. The method according to claim 12, It is characterized in that Saving the inspection results of the code inspection tasks in the deployment tasks under the different environment tags to the indicator lake includes: For each of the environment tags, save the environment tag, the inspection result of the code inspection task in the deployment task under the environment tag, and the identification information of the software package corresponding to the deployment task under the environment tag to the metric lake.

14. The method according to claim 13, wherein, the obtaining the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline from the metric lake includes: querying from the metric lake the inspection result of the code inspection task corresponding to the deployment task in the updated pipeline by using the identification information of the software package of the updated pipeline and the environment tag of the code inspection task for admission inspection specified by the corresponding target admission rule as an index.

15. The method according to claim 12, wherein, the inspection result of the code inspection task saved in the metric lake is applicable to the admission inspection of the deployment task in the first pipeline; the first pipeline is any pipeline including the deployment task specified by the target admission rule.

16. The method according to claim 12, wherein, after not executing the deployment task and stopping the operation of the updated pipeline, the method further includes: outputting the inspection result of the code inspection task corresponding to the deployment task; querying the metric lake at a preset period by using the identification information of the software package of the updated pipeline and the environment tag of the code inspection task for admission inspection corresponding to the corresponding target admission rule as an index to obtain the new inspection result of the code inspection task corresponding to the deployment task in the updated pipeline; determining whether to pass the admission inspection according to the new inspection result of the code inspection task corresponding to the deployment task.

17. An apparatus for running a pipeline, wherein, the apparatus includes: an obtaining module, configured to obtain a target admission rule corresponding to the pipeline to be deployed from preconfigured admission rules; wherein, the preconfigured admission rules are used to specify the deployment tasks for admission inspection and the code inspection tasks corresponding to the deployment tasks; the pipeline includes at least one deployment task; a deployment module, configured to generate an admission node corresponding to the deployment task in the pipeline to obtain an updated pipeline when the pipeline to be deployed includes the deployment task specified by the target admission rule; wherein, the admission node is used to intercept the execution of the deployment task based on the inspection result of the code inspection task; a running module, configured to run the updated pipeline.

18. A computing device cluster, wherein, including at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 16.

19. A computer-readable storage medium, wherein, The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method according to any one of claims 1 to 16.