Container monitoring method and device and computer readable storage medium
By deploying the second monitoring module in the computing node for data acquisition, the problem of excessive network and computing resources consumption in secure container monitoring is solved, and more efficient container monitoring is achieved.
Patent Information
- Application Number
- CN202410178041.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-02-07
- Publication Date
- 2025-05-23
AI Technical Summary
When the number of secure containers deployed on the host is large, each secure container deploys a monitoring agent, resulting in excessive consumption of network resources and computing resources.
A first container and a first monitoring module are deployed in the computing node, and a second monitoring module is deployed in the first container. The second monitoring module is mainly used for data acquisition, does not involve data interaction with the monitoring service module, reduces network bandwidth consumption, and avoids processing data to reduce computing resource consumption.
The network resources and computing resources consumed for monitoring secure containers are reduced, and the efficiency of container monitoring is improved.
Smart Images

Figure CN120029844A_ABST
Abstract
Description
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 21, 2023, with application number 202311558332.7 and application name “A mixing container observation method and device”, all contents of which are incorporated by reference in this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud computing technology, and in particular to a container monitoring method, device, and computer-readable storage medium. Background Art
[0003] Currently, containers are deployed on hosts, and isolation between applications is achieved by isolating the operating environments between containers. For example, the operating environments between secure containers are isolated through the virtualization layer, and each secure container has its own microkernel.
[0004] To ensure the normal operation of applications in secure containers, it is necessary to deploy monitoring agents in secure containers to monitor the running status of secure containers when running applications and report the running status. However, when there are a large number of secure containers deployed on the host, a monitoring agent is deployed for each secure container, and each monitoring agent reports the running status separately, resulting in the consumption of a large amount of network resources. In addition, the monitoring agent deployed for each secure container to monitor the running status involves data collection and data processing operations, which will consume additional computing resources of the secure container. Summary of the invention
[0005] Embodiments of the present application provide a container monitoring method, device, and computer-readable storage medium to reduce network resources and computing resources consumed by monitoring secure containers.
[0006] In a first aspect, an embodiment of the present application provides a container monitoring method, which is applied to a computing node deployed with a first container and a first monitoring module. The first container is deployed with a second monitoring module. When monitoring the first container, the first monitoring module obtains first monitoring information and sends the first monitoring information to the second monitoring module, where the first monitoring information is used to indicate the application running in the first container to be monitored. The second monitoring module receives the first monitoring information sent by the first monitoring module, samples the first operating data of the application running in the first container according to the first monitoring information, and sends the first operating data to the first monitoring module. The first monitoring module receives the first operating data sent by the second monitoring module, and feeds back a first monitoring result indicating the operating status of the application running in the first container according to the first operating data.
[0007] Regarding the deployment of monitoring modules in each security container, since each monitoring module separately performs data collection, data processing, and reports the running status to the monitoring service module, it causes the problem of consuming a large amount of network resources and computing resources. In the embodiments of the present application, the second monitoring module deployed in the first container is mainly used for data collection, without reporting monitoring results, and does not involve data interaction with the monitoring service module. In this way, it is possible to reduce the consumption of network bandwidth due to data transmission between a single second monitoring module and the monitoring service module. At the same time, it is possible to avoid consuming the computing resources of the first container by the second monitoring module for data processing, and thus the computing resources can be reduced.
[0008] In a possible implementation manner, the specific implementation is as follows: The first monitoring information includes monitoring parameters and an application identifier for indicating the application.
[0009] In this way, through the first monitoring information including monitoring parameters and the application identifier, the application to be monitored and the parameters to be collected are determined, and accurate monitoring of the application is realized.
[0010] In a possible implementation manner, the specific implementation is as follows: The monitoring parameters include at least one of network parameters, performance parameters, or running parameters.
[0011] In this way, in container monitoring, monitoring one or more of the network situation, performance situation, and running situation of the application running in the container can monitor the running situation of the application running in the container from multiple aspects.
[0012] In a possible implementation manner, the specific implementation is as follows: The correspondence between the containers in the computing node and the applications deployed on the containers is stored in the interface service module. When the first monitoring module obtains the first monitoring information, the first monitoring module obtains the application identifier from the monitoring service module, and obtains the container information corresponding to the application identifier from the interface service module according to the application identifier. The container information includes the container type and the container identifier, and the first monitoring module sends the first monitoring information to the second monitoring module corresponding to the container identifier according to the container identifier.
[0013] Based on this possible implementation manner, the first monitoring module obtains the application identifier from the monitoring service module. In this way, in the case where there are many applications running in the computing node, the applications to be monitored among the applications running in the computing node can be accurately identified by means of the application identifier, avoiding mis-monitoring of the applications by the first monitoring module. And based on the application identifier, through the correspondence between the containers included in the interface service module and the applications deployed on the containers, the container identifier of the container running the application is obtained, and the first monitoring information is sent to the second monitoring module corresponding to the container identifier. In this way, the container to be monitored can be accurately determined, avoiding mis-monitoring of the container by the first monitoring module.
[0014] In a possible implementation, the first monitoring module sends a second monitoring module deployment request to the monitoring service module according to the container identifier. The monitoring service module receives the second monitoring module deployment request and deploys the second monitoring module in the first container corresponding to the container identifier.
[0015] In this way, the second monitoring module is deployed in the first container corresponding to the container identifier in the computing node through the container identifier, thereby achieving accurate deployment of the second monitoring module.
[0016] In a possible implementation, the specific implementation is: when the first monitoring module obtains the first monitoring information, the first monitoring module obtains the application identifier from the monitoring service module, obtains the container information corresponding to the application identifier from the interface service module according to the application identifier, and obtains the monitoring parameters.
[0017] Based on this possible implementation method, the first monitoring module obtains the application identifier from the monitoring service module, and obtains the monitoring parameters from the interface service module based on the application identifier to obtain the first monitoring information. In the case where there are many applications running in the computing node, the accuracy of the acquired monitoring information is improved by means of application identifiers, and the applications that need to be monitored among the applications running in the computing node can be accurately identified. This avoids the first monitoring module from mismonitoring the application. Furthermore, in the case where there are many applications that need to be monitored in the computing node, and different applications correspond to different monitoring parameters, the method of obtaining monitoring information from the monitoring service module and the interface service module does not occupy the storage resources of the first monitoring module.
[0018] In a possible implementation, the specific implementation is as follows: the first monitoring module includes a correspondence between an application identifier and a container identifier. When the first monitoring module sends the first monitoring information to the second monitoring module, the first monitoring module obtains the container identifier based on the application identifier in the first monitoring information and the correspondence between the application identifier and the container identifier. The first monitoring module sends the first monitoring information to the second monitoring module corresponding to the container identifier.
[0019] Based on this possible implementation manner, a first container running an application to be monitored is quickly determined, so that first monitoring information is quickly and accurately sent.
[0020] In a possible implementation, the specific implementation is as follows: after the second monitoring module is started, the second monitoring module sends a connection request to the first monitoring module. The first monitoring module responds to the connection request and establishes a network channel with the second monitoring module. The second monitoring module sends a registration request to the first monitoring module through the network channel. The first monitoring module responds to the registration request, obtains the container identifier of the first container carried in the registration request and the application identifier of the application running on the first container, associates the container identifier of the first container with the application identifier of the application running on the first container, and establishes a corresponding relationship between the application identifier and the container identifier.
[0021] Based on this possible implementation, a corresponding relationship between the application identifier and the container identifier is established through the registration request sent by the second monitoring module. In this way, the application running on the first container is quickly obtained. Later, when the first monitoring module sends the first monitoring information to the second monitoring module, the first container running the application to be monitored can be quickly determined through the corresponding relationship between the application identifier and the container identifier, so as to achieve the rapid and accurate sending of the first monitoring information.
[0022] In one possible implementation, the second monitoring module samples the first running data of the application running in the first container according to the first monitoring information. Specifically, the second monitoring module collects the actual monitoring parameters of the first container during the execution of the application by the first container from the microkernel of the first container according to the monitoring parameters in the first monitoring information to obtain the first running data.
[0023] Based on this possible implementation, the second monitoring module obtains the first running data from the microkernel of the first container. In this way, when the first containers are isolated from each other, the first monitoring module can still obtain the first running data of the first container when running the application, thereby realizing the monitoring of the container in the secure container scenario.
[0024] In a possible implementation, the first monitoring module feeds back the first monitoring result based on the first operating data, which is specifically implemented as follows: the first monitoring module processes the first operating data to obtain the actual monitoring parameters of the first container when the application is running. The actual monitoring parameters are compared with the preset monitoring parameter thresholds to obtain the operating status of the application running in the first container. Based on the operating status and the actual monitoring parameters, the first monitoring result is fed back to the monitoring service module.
[0025] Based on this possible implementation, the first monitoring module processes the first operating data to obtain a first monitoring result. By feeding back the first monitoring result including the operating status, the monitoring service module can intuitively display the first monitoring result of the first container.
[0026] In a possible implementation, the specific implementation is: when the computing node is also deployed with a second container, the first monitoring module collects the second operation data of the second container running the application according to the monitoring parameters indicated by the second monitoring information. And the second monitoring result is fed back according to the second operation data. The second monitoring result is used to indicate the running status of the second container running the application.
[0027] In this way, when the computing node includes the first container and the second container, the first monitoring module acquires the operation data according to the operation data acquisition modes corresponding to the first container and the second container, thereby implementing container monitoring in a mixed environment of the first container and the second container.
[0028] In a second aspect, an embodiment of the present application provides a container monitoring device, which may be a computing device that executes a container monitoring method, or a chip or system on chip in a computing device. The container monitoring device may implement the functional module of the method in the first aspect or any possible implementation of the first aspect. The container monitoring device may implement the functions performed by the computing device in the first aspect or any possible implementation of the first aspect, and the functional module may be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example: a first container monitoring module and a second container monitoring module.
[0029] The first monitoring module is used to obtain first monitoring information for indicating an application for monitoring the running of the first container, and send the first monitoring information to the second monitoring module.
[0030] The second monitoring module is used to sample first running data of the application running in the first container according to the first monitoring information, and return the first running data to the first monitoring module.
[0031] The first monitoring module is used to feed back a first monitoring result according to the first operation data, wherein the first monitoring result is used to indicate the operation state of the first container during the application operation.
[0032] Specifically, the related processing actions and beneficial effects of the first monitoring module and the second monitoring module can be referred to in the first aspect or any possible implementation manner of the first aspect, and will not be elaborated herein.
[0033] In a third aspect, an embodiment of the present application provides a computing device. The computing device includes a processor and a memory, wherein the memory is used to store computer execution instructions and data necessary for the computing device. The processor is used to instruct the computing execution instructions and data necessary for the computing device stored in the memory to enable the computing device to perform the method in the first aspect or any possible implementation of the first aspect.
[0034] In a fourth aspect, an embodiment of the present application provides a computing device cluster. The computing device cluster includes at least one computing device. Each computing device includes a processor and a memory. The processor of at least one computing device is used to execute instructions stored in the memory of at least one computing device, so that the computing device cluster performs the method in the first aspect or any possible implementation of the first aspect.
[0035] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, including computer program instructions. When the computer program instructions are executed by a computing device or a computing device cluster, the computing device or the computing device cluster executes the computer program instructions stored in the computer-readable storage medium to perform the method in the first aspect or any possible implementation of the first aspect.
[0036] In a sixth aspect, an embodiment of the present application provides a computer program product. When the instruction is executed by a computing device or a computing device cluster, the computing device or the computing device cluster executes the method in the first aspect or any possible implementation of the first aspect.
[0037] The technical effects brought about by any design method from the second aspect to the sixth aspect can refer to the technical effects brought about from the first aspect to the first aspect or by different design methods, and will not be repeated here.
[0038] Based on the implementations provided in the above aspects, the present application can be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 This is a diagram of container monitoring using eBPF technology in an application container.
[0040] Figure 2 This is a diagram of container monitoring failure using eBPF technology in a secure container;
[0041] Figure 3 It is a schematic diagram of container monitoring of eBPF technology under a secure container in the related technology;
[0042] Figure 4 A schematic diagram of the system architecture of the container monitoring method provided in an embodiment of the present application;
[0043] Figure 5 A schematic diagram of a process flow of a container monitoring method provided in an embodiment of the present application;
[0044] Figure 6 A schematic diagram of a system architecture for container monitoring in a mixed container scenario provided in an embodiment of the present application;
[0045] Figure 7A schematic flow chart of a container monitoring method in a mixed container scenario provided in an embodiment of the present application;
[0046] Figure 8 A schematic diagram of a flow chart of a method for establishing a network channel provided in an embodiment of the present application;
[0047] Fig. 9 A flowchart of a monitoring information acquisition method provided in an embodiment of the present application;
[0048] Fig.10 A schematic diagram of the process of container monitoring provided in an embodiment of the present application;
[0049] Fig.11 A schematic diagram of the structure of a container monitoring device provided in an embodiment of the present application;
[0050] Fig.12 A schematic diagram of the structure of a container monitoring system provided in an embodiment of the present application;
[0051] Fig.13 A schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0052] Fig.14 A schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0053] Fig.15 A schematic diagram of network connections between computing devices in a computing device cluster provided in an embodiment of the present application. DETAILED DESCRIPTION
[0054] First, several terms in the embodiments of the present application are explained as follows:
[0055] Kubernetes: Also known as k8s, k8s cluster or cluster. An open source container orchestration and scheduling management platform.
[0056] Container technology: a process isolation technology. Through container technology, different applications can run in isolated containers on the same operating system. Among them, containers are managed and resource scheduled through a scheduling management platform.
[0057] Depending on the isolation method, containers can be divided into application containers and security containers.
[0058] Application container: A container that uses the kernel namespace for process isolation and uses resource restrictions from control groups (cgroups). Understandably, each application container deployed on the same device shares a kernel.
[0059] Secure container: A container that uses a virtualization layer to isolate the operating environment between containers. Each secure container has its own microkernel, and the operations of secure containers deployed on the same device are not affected.
[0060] Container monitoring: The process of collecting metrics for microservices-based applications running on containers.
[0061] Extended Berkeley Packet Filter (eBPF): A container monitoring technology that can run eBPF code in the kernel without modifying the kernel code of the operating system to collect operating data of microservice-based applications running in containers.
[0062] In the application container scenario, based on eBPF technology, an eBPF proxy module can be deployed in the operating system where the container is located. The running data of the container running the application collected by the eBPF proxy module can be used to report the monitoring results.
[0063] For example, Figure 1 As shown, Figure 1 This is a diagram of container monitoring using eBPF technology in an application container scenario. An eBPF agent module 102 and an application container 103 are deployed in the operating system. The eBPF agent module 102 obtains the monitoring information of the application that needs to be detected from the monitoring service module 101. According to the monitoring information, the kernel interface (application programming interface, API) is called to issue the configuration of the eBPF kernel probe 104 (eBPF probe). The eBPF Probe 104 collects the running data of the application container 103 running the application by embedding points in the kernel 105. The eBPF agent module 102 performs data calculations based on the collected running data to obtain monitoring results, and reports the monitoring results to the monitoring service module 101.
[0064] The kernel probe adds a probe point in the kernel 105, and adds the program code to be executed to the probe point. When the kernel 105 executes to the probe point, the kernel 105 execution is interrupted, and the program code at the probe point is executed. When the program code at the probe point is executed, the kernel 105 continues to execute. It can be understood that the probe point can also be called a buried point.
[0065] In the secure container scenario, since the secure container 106 includes an independently running kernel, the eBPF agent module 102 and the secure container 106 no longer share a kernel 105. Figure 2As shown, at this time, by embedding points in the kernel 105 through the eBPF proxy module 102, only the network parameters of the secure container 106 can be obtained. However, the running data such as the process call and performance of the secure container 106 cannot be obtained.
[0066] Based on this, the related technology deploys the eBPF proxy module 102 in each secure container 106 to implement the monitoring of the secure container 106. Figure 3 As shown, Figure 3 1 is a schematic diagram of the application of eBPF technology in the security container scenario in the related art. Each security container 106 deploys an eBPF proxy module 102. The eBPF proxy module 102 deployed in each security container 106 refers to Figure 1 The monitoring process provided reports the monitoring results of each secure container 106 to the monitoring service module 101. It can be seen that the eBPF proxy module 102 deployed in each secure container 106 performs data acquisition and data reporting operations, which consumes a large amount of network bandwidth and occupies the network resources of the container. At the same time, the eBPF proxy module 102 deployed in each secure container 106 performs data calculations, which consumes a large amount of computing resources and reduces the computing performance of the container.
[0067] In order to solve the problem of consuming more network resources and computing resources in the scenario of secure container monitoring, an embodiment of the present application provides a container monitoring method. The method deploys a first container and a first monitoring module on a computing node, and a second monitoring module is deployed in the first container. During the container monitoring process, the second monitoring module performs data collection according to the monitoring information sent by the first monitoring module, and the first monitoring module obtains the data fed back by the second monitoring module and reports the data. Since the second monitoring module deployed in the present application is mainly used for data collection, it does not involve data interaction with the monitoring service module, but sends the collected operation data to the first monitoring module, and the first monitoring module performs data calculation and data upload. In this way, the consumption of network bandwidth due to data transmission between a single second monitoring module and a monitoring service module can be reduced. At the same time, it is avoided that the second monitoring module processes data and consumes the computing resources of the first container, thereby reducing computing resources and network resources.
[0068] To better illustrate the container monitoring method provided in the embodiment of the present application, taking the container running the application including the first container as an example, the embodiment of the present application provides a system architecture for container monitoring. Figure 4 As shown, Figure 4 4 is a schematic diagram of a system architecture of container monitoring provided in an embodiment of the present application. The system architecture of container monitoring shown includes a monitoring service module 410 , an interface service module 420 and a computing node 430 .
[0069] like Figure 4As shown, a first monitoring module 431 and a first container 432 are deployed in the computing node 430 , and a second monitoring module 4321 is deployed in the first container 432 .
[0070] The monitoring service module 410 is used to provide monitoring information to the first monitoring module 431 and receive monitoring results returned by the first monitoring module 431 .
[0071] In an optional implementation, the monitoring service module 410 may display the monitoring result returned by the first monitoring module 431 .
[0072] The interface service module 420 is used to provide monitoring information to the first monitoring module 431 .
[0073] The first container 432 includes a secure container for running applications.
[0074] The first monitoring module 431 is used to instruct the second monitoring module 4321 to monitor the first container 432 based on the monitoring information sent by the monitoring service module 410 and the interface service module 420 , and return the monitoring result to the monitoring service module 410 based on the monitoring data returned by the second monitoring module 4321 .
[0075] In a possible implementation, the first monitoring module 431 may be a physical device or a virtual component. When the first monitoring module 431 is a physical device, the first monitoring module 431 may be a computing device in the computing node 430, or a chip in the computing device, etc. When the first monitoring module 431 is a virtual component, the first monitoring module 431 may be a data packet filter. For example, a Berkeley data packet filter, or an extended Berkeley data packet filter. When the first monitoring module 431 is a virtual component, the first monitoring module 431 may be a proxy module. For example, an extended Berkeley data packet filter proxy module.
[0076] The second monitoring module 4321 is used to monitor the first container 432 and return monitoring data to the first monitoring module 431 .
[0077] Similar to the first monitoring module 431, the second monitoring module 4321 can be a virtual component or a physical device. For example, taking the second monitoring module 4321 as a virtual component, the second monitoring module 4321 is a lightweight eBPF proxy module. Lightweight eBPF proxy module characterization The lightweight eBPF proxy module provides the data collection function of eBPF, but does not provide the data reporting and data calculation functions of eBPF.
[0078] When both the first monitoring module 431 and the second monitoring module 4321 are virtual components, data interaction can be carried out between the first monitoring module 431 and the second monitoring module 4321 through a network channel. Or data interaction can be carried out through inter-process communication.
[0079] In an alternative implementation, the network channel can be an inter-virtual machine communication channel. For example, a network channel is established between the first monitoring module 431 and the second monitoring module 4321 through the virtual machine communication interfacesockets (vsock) method. Among them, the vsock method is a virtual machine communication method, which realizes kernel-level virtual machine communication through the socket type for the virtualization environment and is used to establish a network connection between the host and the virtual machine. That is, a network connection is established between the first monitoring module 431 and the second monitoring module 4321 in the embodiments of the present application. Specifically, the method for establishing the network channel can refer to the Figure 8 Flow schematic diagram of the provided network channel establishment method, which will not be elaborated in the embodiments of the present application.
[0080] When both the first monitoring module 431 and the second monitoring module 4321 are physical devices, data interaction can be carried out between the first monitoring module 431 and the second monitoring module 4321 through a wired network channel or a wireless network channel.
[0081] In a possible implementation, to avoid modifying the kernel code of the computing node 430, the first monitoring module 431 is deployed into the operating system of the computing node 430 in the form of a daemonset. The second monitoring module 4321 is deployed in the first container 432 in the sidecar manner.
[0082] The sidecar mode is to add the second monitoring module 4321 to the first container 432 without changing the function of the first container 432, and the second monitoring module 4321 interacts with the corresponding first container 432.
[0083] The daemonset mode is to add a new resource object to the operating system of the computing node 430 and deploy the first monitoring module 431 into the newly added resource object.
[0084] In an alternative implementation, the second monitoring module 4321 can be deployed by the monitoring service module 410.
[0085] Based on Figure 4 The provided system architecture schematic diagram, to better illustrate the container monitoring method provided by the embodiments of the present application, a container monitoring method is provided. This container monitoring method can be applied to Figure 4The computing nodes in the provided system architecture can also be applied to computing devices with data processing capabilities, which is not limited in the present application embodiment. Figure 4 Take the computing nodes in the provided system architecture as an example, Figure 5 As shown, a flow chart of a container monitoring method provided in an embodiment of the present application is provided, and the container monitoring method shown includes at least steps S210 to S240.
[0086] Step S210: The first monitoring module obtains first monitoring information.
[0087] The first monitoring information represents monitoring information of the first container that needs to be monitored.
[0088] The monitoring information includes application information and monitoring parameters. The application information includes application identification or application name, etc. Optionally, the application identification includes a process identifier (piping instrument diagram, PID). The application can be an application program or microservice running in a computing node. The application can also be a task executed in a computing node, such as a process, etc.
[0089] In a possible implementation, the monitoring parameters include one or more of network parameters, performance parameters, or operation parameters.
[0090] The network parameters are used to indicate the network resource usage of the container when running the application. For example, network parameters include network traffic, network bandwidth, average response time, and error rate.
[0091] The error rate indicates the ratio of the number of error requests that occurred when the container executed the application to the total number of requests.
[0092] Network traffic, which indicates the data throughput when the container executes the application.
[0093] The average response time indicates the response rate of the container to requests when executing applications. It can be understood that the larger the average response time, the more likely the container is to have session congestion and the lower the network data transmission rate.
[0094] Performance parameters are used to indicate the resource consumption of containers when running applications, such as computing resources and storage resources. Performance parameters include but are not limited to system calls, call chains, utilization, and saturation.
[0095] The utilization rate is used to indicate the container resource utilization when the container executes the application. The utilization rate includes at least one of the central processing unit (CPU) utilization rate, memory utilization rate and disk utilization rate.
[0096] Saturation is used to indicate the load of the container when executing the application. Saturation includes CPU saturation and memory saturation. Among them, CPU saturation rate is used to indicate the extent to which the CPU is used within a period of time during the execution of the application by the container. Understandably, the higher the CPU saturation of the container, the more limited the CPU processing power. Memory saturation is used to indicate whether the demand for memory when the container executes the application exceeds the memory available to the container. Understandably, when the memory saturation indicates that the demand for memory when the application exceeds the memory available to the container, operations such as memory release are required to reduce the memory usage of the container when executing the application.
[0097] The operation parameters are used to indicate the container health status when the container is running the application, the execution status of the application, etc. The container health status includes the container running, the operation is paused, and the container is stopped. The execution status includes waiting to run, running, and stopped. The operation parameters include the container health status of the container and the execution status of the application.
[0098] In an embodiment of the present application, the first monitoring module may actively request the first monitoring information from the monitoring service module and the interface service module, or the first monitoring module may respond to a monitoring instruction sent by the monitoring service module to obtain the first monitoring information.
[0099] Taking the example of the first monitoring module actively requesting the first monitoring information from the monitoring service module and the interface service module, the first monitoring module requests the application identifier from the monitoring service module. The first monitoring module requests the monitoring parameters from the interface service module based on the application identifier, and the first monitoring module determines the application identifier and the monitoring parameters as the first monitoring information. Fig. 9 The monitoring information acquisition process provided is not described in detail in the embodiments of the present application.
[0100] Step S220: The first monitoring module sends first monitoring information to the second monitoring module.
[0101] In an embodiment of the present application, since there may be multiple containers in a computing node, each container may run different applications. Therefore, after obtaining the first monitoring information, the first monitoring module needs to determine the container that runs the application that needs to be monitored. In the case where the container of the application that needs to be monitored includes the first container, the first monitoring module sends the first monitoring information to the second monitoring module deployed in the first container. In this way, by obtaining the operating data of the container that runs the application that needs to be monitored, it is avoided to monitor the container that does not run the application that needs to be monitored, reduce the amount of data processing, and achieve accurate monitoring of the container.
[0102] In the first possible implementation manner, the first monitoring module determines the container running the application to be monitored based on the application identifier included in the first monitoring information and the corresponding relationship between the application identifier and the container identifier included in the first monitoring module.
[0103] For example, after obtaining the first monitoring information, the first monitoring module obtains the application identifier included in the first monitoring information, and determines the first container associated with the application identifier through the corresponding relationship between the application identifier and the container identifier.
[0104] In an example, the corresponding relationship between the application identifier and the container identifier is used to indicate the mapping relationship between the application identifier of the application running in the computing node and the container identifier of the container running the application. The corresponding relationship between the application identifier and the container identifier can be created with reference to the Figure 8 embodiments provided below. The embodiments of the present application will not be described in detail here.
[0105] In the second possible implementation manner, the interface service module includes the corresponding relationship between the application identifier and the container information in the computing node. For example, the interface service module stores the container information corresponding to each computing node identifier in the form of a list. The container information includes the container identifier and the container type in the computing node where the first monitoring module is located. The first monitoring module can request the container running the application to be monitored from the interface service module based on the application identifier.
[0106] For example, the first monitoring module requests the container information associated with the application identifier from the interface service module, and determines the first container running the application to be monitored according to the container identifier in the container information. The first monitoring module sends the first monitoring information to the second monitoring module deployed in the first container.
[0107] Step S230, the second monitoring module samples the first running data of the application running in the first container according to the monitoring information, and sends the first running data to the first monitoring module.
[0108] In the embodiments of the present application, the first running data indicates the running data of the application running in the first container.
[0109] In the embodiments of the present application, the second monitoring module samples the running data according to the monitoring parameters specified in the monitoring information, and obtains the running data from the microkernel of the secure container running the application. The second monitoring module sends the obtained running data to the first monitoring module. It can be understood that the running data is used to indicate the parameters of the container when running the application. For example, the running data includes at least one of network communication packet data, kernel resource occupancy data, system call data, and application status data when the container runs the application.
[0110] Among them, the network communication message data is used to indicate the total number of requests, the number of error requests, network bandwidth, and average response time, etc.
[0111] Kernel resource usage data is used to indicate the CPU idle time, memory usage, and CPU load value of the container when running applications.
[0112] The system call data is used to indicate remote procedure call information, wherein the remote procedure call information is used to indicate the situation where other applications need to be called when the execution application is running.
[0113] In a possible implementation, the second monitoring module may deploy a kernel probe in the microkernel of the first container, and collect first running data of the application running in the first container through the kernel probe.
[0114] For example, after receiving the monitoring information sent by the first monitoring module, the second monitoring module deploys a kernel probe in the microkernel of the first container and collects first running data of the application running in the first container through the kernel probe.
[0115] For another example, the second monitoring module performs sampling through a kernel probe at every preset time interval to obtain first running data of the application running in the first container within the preset time interval.
[0116] In a second possible implementation manner, the second monitoring module deploys a hook function in the microkernel of the first container, and captures first running data of the application running in the first container through the hook function.
[0117] Step S240: The first monitoring module obtains a first monitoring result according to the first operating data and feeds back the first monitoring result.
[0118] The first monitoring result indicates a monitoring result of the first container running the application.
[0119] In a first possible implementation manner, the monitoring result includes operation data.
[0120] For example, the monitoring result includes an application identifier of an application to be monitored and running data of a container running the application to be monitored.
[0121] For another example, when an application is run by multiple containers, the monitoring result includes running data of the applications run by the multiple containers.
[0122] In a second possible implementation, the monitoring result includes the running state of the container running the application. The running state of the container running the application is used to indicate whether there is at least one of a network anomaly, a performance anomaly, and an operation anomaly when the container runs the application. It is understandable that the network anomaly includes a network disconnection when the container runs the application and a data transmission rate less than a preset transmission rate. The performance anomaly includes a data processing rate less than a preset processing rate or a session congestion when the container runs the application. The operation anomaly includes a failure of the container when the container runs the application, such as a container failure or inactivation.
[0123] For example, after receiving the first running data returned by the second monitoring module, the first monitoring module performs status identification on the first running data to obtain the running status of the application running in the first container, and uses the running status of the application running in the first container as the first monitoring result.
[0124] It should be noted that the two possible implementations of the first monitoring module feeding back the monitoring results are only exemplary and do not constitute a limitation on the container monitoring method provided in the embodiment of the present application. In practical applications, other monitoring result feedback methods can also be used. For example, by combining the first possible implementation method and the second possible implementation method, the monitoring results include the first operating data and the operating status of the container running application.
[0125] In an embodiment of the present application, the first monitoring module can periodically feed back monitoring results to the monitoring service module. For example, the first monitoring module caches the monitoring results. When the number of cached monitoring results is greater than or equal to a preset number threshold, the first monitoring module feeds back the cached monitoring results to the monitoring service module. For another example, the first monitoring module caches the monitoring results. When the cache duration is greater than or equal to a preset cache duration threshold, the first monitoring module feeds back the cached monitoring results to the monitoring service module.
[0126] In an embodiment of the present application, the monitoring service module displays the monitoring result fed back by the first monitoring module. For example, the monitoring service module displays the monitoring result fed back by the first monitoring module in the form of a chart.
[0127] In the embodiment of the present application, a secure container may be deployed in the same computing node 430, such as Figure 5 As shown. A security container and an application container may be deployed in the same computing node 430, such as Figure 6 As shown, Figure 6 Schematic diagram of the system architecture of container monitoring in a mixed container scenario provided by an embodiment of the present application. Figure 4 The system architecture of container monitoring shown in the figure is Figure 6 The system architecture for container monitoring in the mixed container scenario shown also includes a second container 434 .
[0128] The second container 434 includes an application container for running an application.
[0129] Relative to Figure 4 Provided system architecture, Figure 6 In the system architecture shown, the first monitoring module 431 is also used to monitor the second container 434 and feed back the monitoring result of the second container 434 to the monitoring service module 410 .
[0130] based on Figure 6 The system architecture provided by the present application provides a container monitoring method in a mixed container scenario. The container monitoring method in the mixed container scenario can be applied to Figure 6 Alternatively, the container monitoring method in the mixed container scenario can be applied to a computing device with data processing capabilities, which is not limited in the present application embodiment. Figure 6 Take the system architecture shown in the figure as an example. Figure 7 As shown, Figure 7 Schematic diagram of the process of the container monitoring method in the mixed container scenario provided by the embodiment of the present application. Figure 5 Compared to the container monitoring methods shown, Figure 7 The provided container monitoring method in a mixed container scenario also includes step S250.
[0131] Step S250: The first monitoring module collects second operation data, obtains a second monitoring result according to the second operation data, and feeds back the second monitoring result. The first monitoring module collects second operation data during the application operation of the second container based on the monitoring parameters indicated by the second monitoring information, and feeds back the second monitoring result according to the second operation data.
[0132] The second monitoring information represents monitoring information that needs to be monitored by the second container; the second operating data indicates operating data of the application running in the second container; and the second monitoring result indicates a monitoring result of the application running in the second container.
[0133] It should be noted that the above Figure 4 and Figure 6 The drawings are only exemplary and do not constitute a limitation on the container monitoring method provided in the embodiments of the present application. Figure 4 , Figure 6More or fewer modules. For example, computing node 430 may be a physical device, or computing node 430 may be a virtual device. Monitoring service module 410, interface service module 420, first monitoring module 431, first container 432, and second container 434 may be deployed in the same computing node 430. Monitoring service module 410, interface service module 420, first monitoring module 431, first container 432, and second container 434 may also be not completely deployed in the same computing node 430.
[0134] It can be understood that when the monitoring service module 410, the interface service module 420, the first monitoring module 431, the first container 432 and the second container 434 are deployed on the same computing node 430, the monitoring service module 410, the interface service module 420, the first monitoring module 431, the first container 432 and the second container 434 exchange data through inter-process communication.
[0135] In the case where the monitoring service module 410, the interface service module 420, the first monitoring module 431, the first container 432 and the second container 434 are not completely deployed to the same computing node 430, in one example, the monitoring service module 410 and the interface service module 420 are set in the working node A, the first monitoring module 431, the first container 432 and the second container 434 are set in the working node B, and the working node A and the working node B perform data transmission through the network. For example, data transmission is performed between the working node A and the working node B through a wired network. For another example, data transmission is performed between the working node A and the working node B through a wireless network. In another example, the monitoring service module 410 is set in the working node C, the interface service module 420 is set in the working node D, and the first monitoring module 431, the first container 432 and the second container 434 are set in the working node E. Data transmission is performed between the working node C, the working node D and the working node E through the network. Among them, it can be a wired network, and the network can also be a wireless network. In another example, the monitoring service module 410 is set in the working node F, and the interface service module 420, the first monitoring module 431, the first container 432 and the second container 434 are set in the working node G.
[0136] based on Figure 5 as well as Figure 7In the provided embodiment, the computing node is deployed with a first container and a second container, and a second monitoring module is deployed in the first container. During the container monitoring process, the second monitoring module performs data collection according to the monitoring information sent by the first monitoring module, and the first monitoring module obtains the data fed back by the second monitoring module and reports it. Compared with the method in which the monitoring agent deployed in each security container reports data separately, the second monitoring module deployed in the first container in the present application is mainly used for data collection, does not involve data interaction with the monitoring service module, but sends the collected operation data to the first monitoring module, and the first monitoring module performs data calculation and data upload. In this way, the consumption of network bandwidth due to data transmission between a single second monitoring module and the monitoring service module can be reduced. At the same time, the consumption of computing resources of the first container due to data reporting through the second monitoring module is avoided, thereby reducing the occupation of network resources and computing resources.
[0137] In order to better describe the container monitoring method provided in the embodiment of the present application, the deployment method of the second monitoring module is described below.
[0138] In a possible implementation, the monitoring service module calls the interface module, deploys the second monitoring module on the first container, and starts the second monitoring module.
[0139] In one example, after the first container is deployed in the computing node, the monitoring service module calls the interface module to mount the second monitoring module on the first container in a sidecar manner.
[0140] In another example, the first monitoring module sends a second monitoring module deployment request to the monitoring service module. The monitoring service module responds to the second monitoring module deployment request and deploys the second monitoring module on the first container.
[0141] In this example, after the first monitoring module obtains the container information, if it is determined that the container type in the container information includes the first container, the first monitoring module sends a second monitoring module deployment request to the monitoring service module. In this way, if the container in the computing node includes a secure container, the second monitoring module is mounted on the secure container to obtain the running data of each secure container when running the application.
[0142] In the embodiment of the present application, after being started, the second monitoring module sends a connection request to the first monitoring module. The first monitoring module responds to the connection request and establishes a network channel with the second monitoring module.
[0143] In a possible implementation, since there are multiple containers in the computing node, and the first container is included in the container, the kernel is no longer shared between the first monitoring module and the first container, and the first monitoring module cannot obtain the application running on the first container. Although the first monitoring module can request the interface service module for the application running on the first container in the computing node, when the computing node includes a large number of containers, requesting the interface service module for the application running on the first container requires occupying network bandwidth and increasing the duration of container monitoring. Therefore, in order to enable the first monitoring module to quickly obtain the application running on the first container, the second monitoring module can send the application running on the first container where the second monitoring module is located to the first monitoring module, and the first monitoring module saves the application running on the first container. In this way, the application running on the first container is quickly obtained. Subsequently, when the first monitoring module sends the first monitoring information to the second monitoring module, it can quickly determine the first container running the application to be monitored from the saved application running on the first container, so as to achieve the rapid and accurate sending of the first monitoring information.
[0144] In one example, the second monitoring module sends the application running in the first container where the second monitoring module is located to the first monitoring module in the form of a registration request, wherein the registration request includes the container identifier of the first container and the application identifier of the application running on the first container.
[0145] For example, Figure 8 As shown, after the second monitoring module is started, the second monitoring module sends a connection request to the first monitoring module (step S81). The first monitoring module responds to the connection request and establishes a network channel with the second monitoring module (step S82). The second monitoring module generates a registration request based on the container identifier of the first container and the application identifier of the application running on the first container, and sends the registration request to the first monitoring module through the network channel (step S83). The first monitoring module responds to the registration request, obtains the container identifier of the first container and the application identifier of the application running on the first container carried in the registration request, associates the container identifier of the first container and the application identifier of the application running on the first container, and establishes a corresponding relationship between the application identifier and the container identifier (step S84).
[0146] Next, a method for obtaining the first monitoring information is described by taking the example that the first monitoring module actively requests the first monitoring information from the monitoring service module and the interface service module.
[0147] like Fig. 9As shown, after the first monitoring module is started, it sends connection requests to the monitoring service module and the interface service module respectively (step S2101). The monitoring service module and the interface service module respectively respond to the connection request to establish a connection with the first monitoring module (step S2101). The first monitoring module sends a data request to the monitoring service module (step S2102). The monitoring service module responds to the data request and returns the application identifier of the application to be monitored to the first monitoring module (step S2102). Based on the application identifier returned by the monitoring service module, the first monitoring module requests the interface service module for monitoring parameters and container information corresponding to the application identifier (step S2103). The interface service module returns the monitoring parameters corresponding to the application identifier and the container information corresponding to the application identifier to the first monitoring module (step S2103).
[0148] It should be noted that the embodiments of the present application are Figure 8 The embodiment shown is Fig. 9 The execution order of the embodiments shown is not limited. The above can be adjusted according to the actual application scenario. Figure 8 The execution order between the embodiment shown in FIG. 9 and the embodiment shown in FIG.
[0149] For example, the first monitoring module first executes the above Fig. 9 In the embodiment shown in the figure, after obtaining the first monitoring information, the first monitoring module sends a second monitoring module deployment request to the monitoring service module. The monitoring service module deploys the second monitoring module in the first container. After the second monitoring module is started, the above Figure 8 The embodiment shown.
[0150] For example, you can first execute the above Figure 8 In the embodiment shown in the figure, a connection is established between the first monitoring module and the second monitoring module, and then the first monitoring module executes the above Fig. 9 In the embodiment shown, first monitoring information is obtained.
[0151] For example, you can first execute the above Figure 8 In the embodiment shown in the figure, a connection is established between the first monitoring module and the second monitoring module, and then the first monitoring module executes the above Fig. 9 In the embodiment shown, the first monitoring information is obtained. In the case where the correspondence between the application identifier and the container identifier does not include the application identifier in the first monitoring information, the first monitoring module sends a second monitoring module deployment request to the monitoring service module. The monitoring service module deploys the second monitoring module in the first container. After the second monitoring module is started, the above Figure 8 In the illustrated embodiment, the correspondence between the application identifier and the container identifier is updated.
[0152] In an embodiment of the present application, the first monitoring module obtains an application identifier from the monitoring service module, and obtains monitoring parameters from the interface service module based on the application identifier to obtain first monitoring information. In the case where there are many applications running in the computing node, the accuracy of the acquired monitoring information is improved by means of application identifiers, and the applications that need to be monitored among the applications running in the computing node can be accurately identified. This avoids mis-monitoring of applications by the first monitoring module. Furthermore, in the case where there are many applications that need to be monitored in the computing node, and different applications correspond to different monitoring parameters, the method of obtaining monitoring information from the monitoring service module and the interface service module does not occupy the storage resources of the first monitoring module.
[0153] In the present embodiment, after the first monitoring module obtains the first monitoring information, it sends the first monitoring information to the second monitoring module through the network channel. The second monitoring module collects operation data based on the first monitoring information.
[0154] Next, the method of collecting the first operating parameter is described by taking the example that the second monitoring module collects the first operating data in the form of a kernel probe.
[0155] In the embodiment of the present application, the second monitoring module deploys a kernel probe in the microkernel of the first container according to the monitoring parameters and the application identifier in the first monitoring information. The second monitoring module collects the first running data of the application running in the first container through the kernel probe.
[0156] like Fig.10 As shown, Fig.10 It is a schematic diagram of the collection process of the first operation data provided in an embodiment of the present application. The collection process of the first operation data shown includes steps S2201 to S2203.
[0157] Step S2201: The first monitoring module sends first monitoring information to the second monitoring module.
[0158] Step S2202: The second monitoring module deploys a kernel probe in the microkernel of the first container based on the first monitoring information, and collects first running data of the application running in the first container through the kernel probe.
[0159] In a first possible implementation, the second monitoring module deploys a kernel probe in the microkernel of the first container according to the application identifier in the monitoring information. The second monitoring module sends monitoring parameters to the kernel probe. The kernel probe is buried in the microkernel of the first container, performs data collection operations according to the monitoring parameters, and obtains first operating data corresponding to the monitoring parameters from the microkernel of the first container. After the kernel probe obtains the first operating data, it triggers a data return operation and returns the first operating data of the application running in the first container to the second monitoring module.
[0160] After the kernel probe obtains the first running data, the data return operation can be triggered through a callback function or a hook function.
[0161] In a second possible implementation, the second monitoring module creates a kernel probe for collecting monitoring parameters according to the application identifier and monitoring parameters in the monitoring information. The second monitoring module deploys the kernel probe into the microkernel of the first container. The kernel probe runs in the microkernel of the first container, obtains first operating data corresponding to the monitoring parameters from the microkernel of the first container, and triggers a data return operation to return the first operating data of the application running in the first container to the second monitoring module.
[0162] For example, the second monitoring module creates a kernel probe according to the application identifier and monitoring parameters in the monitoring information, creates a second kernel probe for collecting performance parameters, and creates a third kernel parameter for collecting operating parameters. The second monitoring module deploys the first kernel probe, the second kernel probe, and the third kernel probe into the microkernel of the first container in the form of a daemonset. The first kernel probe collects network communication message data when the first container runs an application. The second kernel probe collects kernel resource data and system call data when the first container runs an application. The third kernel probe collects status data of the application running in the first container.
[0163] Step S2203: the second monitoring module returns the first operation data to the first monitoring module.
[0164] Since there are multiple applications that need to be monitored, or when one application is run by multiple different first containers, in order to ensure the accuracy of the monitoring results, in an embodiment of the present application, when the second monitoring module sends the first running data to the first monitoring module, the container identifier of the first container and the first running data of the application running in the first container are sent to the first monitoring module.
[0165] For example, after acquiring the first operating data, the second monitoring module associates the first operating data with the container identifier of the first container, and then sends the associated first operating data to the first monitoring module.
[0166] Since running the application in the first container is a continuous process, if the running data is collected once, there may be randomness, and it is difficult to determine the running status of the application in the first container. Therefore, in an embodiment of the present application, the second monitoring module can periodically obtain the first running data of the first container in a cycle through the kernel probe until the application is executed, or when the stop command sent by the first monitoring module is received, the running data collection is stopped. In this way, by periodically obtaining the first running data, problems that occur during the running of the application in the first container can be discovered in a timely manner to ensure the normal operation of the container.
[0167] In one example, the first monitoring module processes the received first operation data, and sends a stop collection instruction to the second monitoring module when it is determined that the application to be monitored has completed operation or the first container has stopped operating.
[0168] In another example, when the first monitoring module receives a stop monitoring instruction sent by the monitoring service module, it sends a stop acquisition instruction to the second monitoring module. The stop monitoring instruction may be input by a user. The stop monitoring instruction may also be triggered by the monitoring service module.
[0169] In the embodiment of the present application, the second monitoring module obtains the first running data from the microkernel of the first container by means of a kernel probe. In this way, when the first containers are isolated from each other, the first monitoring module can still obtain the first running data of the first container when running the application, thereby realizing the monitoring of the container in the secure container scenario.
[0170] After receiving the first operation data returned by the second monitoring module, the first monitoring module executes the above step S230 to feed back the first monitoring result.
[0171] Next, the first monitoring module will be described to feedback the first monitoring result according to the first operation data. Fig.10 As shown, the first monitoring module obtains a first monitoring result based on the first operation data returned by the second monitoring module, and feeds back the first monitoring result to the monitoring service module. The monitoring service module displays the first monitoring result.
[0172] First, taking the example that the first monitoring result includes the operating status, the first monitoring module feeding back the first monitoring result according to the first operating data is described.
[0173] In the embodiment of the present application, the first monitoring module can identify the state of the first running data, obtain the running state of the application running in the first container, and feedback the first monitoring result. Alternatively, after the first monitoring module determines the running state, if the running state of the application running in the first container meets the preset requirements, the first monitoring result is fed back.
[0174] In a possible implementation, the preset requirement may be that there is no abnormality when the first container runs the application. It is understandable that there is no abnormality when the first container runs the application may be that there is no network abnormality, no performance abnormality, and no operation abnormality when the first container runs the application.
[0175] For example, the first monitoring module performs status identification on the first operation data to obtain the operation status of the first container operation application. When the operation status of the first container operation application indicates that there is no network abnormality, no performance abnormality, and no operation abnormality when the first container operation application is running, it is determined that the operation status of the first container operation application meets the preset requirements. The operation status of the first container operation application is used as the first monitoring result.
[0176] In the embodiment of the present application, there are at least the following two possible implementation methods for the first monitoring module to perform status identification on the first operating data.
[0177] In a first possible implementation manner, the first monitoring module performs status recognition on the first running data by means of template matching to obtain the running status of the application running in the first container.
[0178] For example, the first monitoring module determines the benchmark operating data that matches the first operating data, determines the operating state corresponding to the benchmark operating data through the mapping relationship between the pre-stored benchmark operating data and the state, and determines the operating state corresponding to the benchmark operating data as the operating state of the first container operating application.
[0179] The mapping relationship between the reference operating data and the state is used to indicate the mapping relationship between the reference operating data and the corresponding operating state.
[0180] It is understandable that the first monitoring module pre-stores a plurality of reference operating data. The reference operating data that matches the first operating data may be the reference operating data having the greatest similarity to the first operating data.
[0181] In a second possible implementation, the first monitoring module identifies the state of the first operating data by means of data processing. The data processing includes one or more of data filtering, aggregate calculation, time average processing, ratio calculation, and statistical calculation. Among them, the statistical calculation includes average value calculation, determination of maximum value, determination of minimum value, and determination of mode, etc. Among them, the aggregate calculation can be one or more of calculation of total number, calculation of average value, and determination of maximum value.
[0182] For example, the first monitoring module processes the first operating data to obtain actual monitoring parameters of the first container when the application is running, and compares the actual monitoring parameters with a preset monitoring parameter threshold to obtain the operating status of the first container when the application is running.
[0183] Exemplarily, taking network parameters as an example, the first monitoring module analyzes the network communication message data in the first operation data to obtain network traffic, network bandwidth, average response time, total number of requests, and number of error requests. The first monitoring module obtains the error rate by (number of error requests / total number of requests)*100%, and determines the error rate, network traffic, network bandwidth, and average response time as actual network parameters.
[0184] Exemplarily, taking performance parameters as an example, the first monitoring module obtains CPU usage, used memory, memory usage, CPU load and CPU idle time based on the kernel resource usage data and system call data in the first operation data. The first monitoring module obtains CPU utilization, memory utilization, CPU saturation and memory saturation based on CPU usage, memory usage, CPU load and CPU idle time. For example, the first monitoring module averages the CPU usage to obtain CPU utilization. For example, the first monitoring module performs time-averaged processing on the CPU load to obtain CPU saturation. For example, the first monitoring module calculates the ratio of used memory to the total memory of the first container to obtain memory saturation.
[0185] It is understandable that when the actual monitoring parameters meet the preset monitoring parameter threshold, the running state of the application running in the first container is determined to be normal. When the actual monitoring parameters do not meet the preset monitoring parameter threshold, the running state of the application running in the first container is determined to be abnormal. Exemplarily, taking the performance parameter as an example, the first monitoring module compares the actual performance parameter with the preset performance parameter threshold. When the actual performance parameter is less than or equal to the preset performance parameter threshold, it is determined that the performance is normal when the first container runs the application. When the actual performance parameter is greater than the preset performance parameter threshold, it is determined that there is a performance abnormality when the first container runs the application.
[0186] Next, taking the example that the first monitoring result includes the operating state and the first operating data, the first monitoring result fed back by the first monitoring module according to the first operating data is described.
[0187] In a first possible implementation, the first monitoring module obtains the running state of the application running in the first container, and determines the running state of the application running in the first container and the first running data as the first monitoring result.
[0188] For example, the first monitoring module receives the first operating data returned by the second monitoring module. The first monitoring module processes the first operating data to obtain the actual monitoring parameters of the container running the application in the computing node. The actual monitoring parameters are compared with the preset monitoring parameter thresholds to obtain the operating status of the container running the application in the computing node. The operating status of the first container running the application and the first operating data are respectively associated with the application identifier to obtain the first monitoring result.
[0189] In a second possible implementation, the first monitoring module obtains the running state of the application running in the first container, and when the running state of the application running in the first container does not meet the preset requirement, the running state of the application running in the first container and the first running data are used as the first monitoring result.
[0190] In a third possible implementation, the first monitoring module caches the received first operation data after receiving the first operation data returned by the second monitoring module. When the amount of cached first operation data is greater than or equal to a preset amount threshold, or the cache duration is greater than or equal to a preset cache duration threshold, the first monitoring module identifies the state of the cached first operation data and obtains the operation state of the first container running application. The operation state of the first container running application and the first operation data are determined as the first monitoring result.
[0191] In the embodiment of the present application, the first monitoring module processes the first operating data to obtain a first monitoring result. By feeding back the first monitoring result including the operating status, the monitoring service module can intuitively display the first monitoring result of the first container.
[0192] It should be noted that the above container monitoring method is implemented when the container running the application includes the first container. It is understandable that the computing node may also include a second container, that is, the computing node includes the application container. Correspondingly, the container running the application may also include the second container, as described above. Figure 6 In the case where the container running the application also includes a second container, the first monitoring module refers to the above Figure 1 In the provided embodiment, second operation data of the second container when running the application is collected, and a second monitoring result is fed back based on the second operation data.
[0193] In a first possible implementation manner, when the container for running the application also includes a second container, the first monitoring module refers to the above Figure 7 In the provided embodiment, the first monitoring result and the second monitoring result are fed back to the monitoring service module.
[0194] In a second possible implementation manner, when the container running the application includes the first container or the second container, the first monitoring module feeds back the first monitoring result or the second monitoring result to the monitoring service module.
[0195] In one example, after the first monitoring module obtains the container information, it identifies the container type according to the container information. In the case where the container type is a security container, the first monitoring module executes the above steps S220 to S240 and feeds back the first monitoring result to the monitoring service module. In the case where the container type is an application container, the first monitoring module refers to the above steps S220 to S240. Figure 1 The provided embodiment feeds back the second monitoring result to the monitoring service module. In this way, in a mixed environment of application containers and security containers, the first monitoring module selects a corresponding method according to the container type to obtain operation data. Container monitoring in a mixed environment of application containers and security containers is realized.
[0196] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the various modules in the computing node 430. It is understandable that each module, such as the first monitoring module, and the second monitoring module, etc., in order to realize the above functions, includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should be easily aware that, in conjunction with the various schematic algorithm steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but this implementation should not be considered to exceed the scope of the present application.
[0197] The embodiment of the present application can group the functional modules of the computing node 430 according to the above method example. For example, each functional module can be grouped according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the grouping and naming of modules in the embodiment of the present application is schematic and is only a logical functional grouping. There may be other grouping methods in actual implementation. The computing node 430 can also be named as the container monitoring device 11. The container monitoring device 11 may include different Figure 4 and Figure 7 The modules shown.
[0198] like Fig.11 As shown, Fig.11 1 is a schematic diagram of the structure of a container monitoring device 11 provided in an embodiment of the present application. The container monitoring device 11 shown includes:
[0199] The first monitoring module 111 is used to obtain first monitoring information for indicating the application running on the first container, and send the first monitoring information to the second monitoring module 112. For example, the first monitoring module executes Figure 5 Steps S210 to S220 in .
[0200] The second monitoring module 112 is used to sample the first operation data of the application running in the first container according to the first monitoring information, and send the first operation data to the first monitoring module 111. For example, the second monitoring module executes Figure 5 Step S230 in .
[0201] The first monitoring module 111 is used to feedback a first monitoring result according to the first operation data. The first monitoring result is used to indicate the operation status of the first container during the application operation. For example, the first monitoring module executes Figure 5 Step S240 in .
[0202] The first monitoring module 111 and the second monitoring module 112 can be implemented by software or hardware. Exemplarily, the implementation of the first monitoring module 111 is introduced below by taking the first monitoring module 111 as an example. Similarly, the implementation of the first monitoring module 111 can be referred to for the second monitoring module 112.
[0203] As an example of a software functional unit, the first monitoring module 111 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance may be one or more. For example, the first monitoring module 111 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple data centers with similar geographical locations. Generally, a region may include multiple AZs.
[0204] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0205] As an example of a hardware functional unit, the first monitoring module 111 may include at least one computing device, such as a server, etc. Alternatively, the first monitoring module 111 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0206] The multiple computing devices included in the first monitoring module 111 can be distributed in the same region or in different regions. The multiple computing devices included in the first monitoring module 111 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the first monitoring module 111 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0207] It should be noted that, in other embodiments, the first monitoring module 111 can be used to execute any step in the container monitoring method. The second monitoring module 112 can be used to execute any step in the container monitoring method. The steps that the first monitoring module 111 and the second monitoring module 112 are responsible for implementing can be specified as needed. The first monitoring module 111 and the second monitoring module 112 respectively implement different steps in the container monitoring method to achieve all functions of the container monitoring device 11.
[0208] The embodiment of the present application also provides a device provided with the above Fig.11 The container monitoring system 12 of the container monitoring device 11 is provided. Fig.12 As shown, Fig.12 is a schematic diagram of the structure of a container monitoring system provided in an embodiment of the present application. The container monitoring system 12 shown includes a container monitoring device 11 and a cluster service device 121 .
[0209] The cluster service device 121 is used to provide the first container information to the container monitoring device 11, receive the first monitoring result fed back by the container monitoring device 11, and display the first monitoring result.
[0210] The container monitoring device 11 is used to obtain first monitoring information indicating the application running in the first container, send the first monitoring information to the second monitoring module, sample first running data of the application according to the first monitoring information, and feedback the first monitoring result to the cluster service device 121 according to the first running data. For example, the container monitoring device 11 executes the above Figure 5 Steps S210 to S240 in .
[0211] The container monitoring device 11 and the cluster service device 121 can be implemented by software or hardware. As an example, the implementation of the container monitoring device 11 is described below. Similarly, the implementation of the cluster service device 121 can refer to the implementation of the container monitoring device 11.
[0212] As an example of a software functional unit, the container monitoring device 11 may include code running on a computing instance. The computing instance may be at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing device may be one or more. For example, the container monitoring device 11 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the application may be distributed in the same region or in different regions. The multiple hosts / virtual machines / containers used to run the code may be distributed in the same AZ or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Typically, a region may include multiple AZs.
[0213] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same VPC or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway must be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0214] As an example of a hardware functional unit, the container monitoring device 11 may include at least one computing device, such as a server, etc. Alternatively, the container monitoring device 11 may also be a device implemented by ASIC or PLD, etc. The PLD may be implemented by CPLD, FPGA, GAL or any combination thereof.
[0215] The multiple computing devices included in the container monitoring device 11 can be distributed in the same region or in different regions. The multiple computing devices included in the container monitoring device 11 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the container monitoring device 11 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0216] The embodiment of the present application also provides a computing device for executing the above container monitoring method.
[0217] In one example, the computing device may include: Fig.11 The container monitoring device 11 shown in FIG. 1 includes a first monitoring module 111 and a second monitoring module 112 .
[0218] In another indication, Fig.13 As shown, the computing device 13 includes a bus 132, a processor 134, a memory 136, and a communication interface 138. The processor 134, the memory 136, and the communication interface 138 communicate with each other through the bus 132. The computing device 13 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors 134 and memories 136 in the computing device 13.
[0219] The bus 132 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.13 The bus 132 is represented by only one line, but it does not mean that there is only one bus or one type of bus. The bus 132 may include a path for transmitting information between various components of the computing device 13 (eg, the memory 136, the processor 134, and the communication interface 138).
[0220] The processor 134 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0221] In the present application, the processor 134 may execute the above Figure 5 The container monitoring method provided includes, for example, obtaining first monitoring information and sending the first monitoring information to a second monitoring module, controlling the second monitoring module to collect first operation data of an application running in a first container, and feeding back a first monitoring result according to the first operation data.
[0222] In the present application, the processor 134 may execute the above Figure 7 A container monitoring method is provided. For example, first monitoring information and second monitoring information are obtained, and the first monitoring information is sent to a second monitoring module. Second operation data of an application running in a second container is collected according to the second monitoring information, and the second monitoring module is controlled to collect first operation data of an application running in a first container. A first monitoring result is fed back according to the first operation data, and a second monitoring result is fed back according to the second operation data.
[0223] The memory 136 may include a volatile memory, such as a random access memory (RAM). The processor 134 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0224] The memory 136 stores executable program codes, and the processor 134 executes the executable program codes to respectively implement the functions of the first monitoring module 111 and the second monitoring module 112, thereby implementing the container monitoring method. That is, the memory 136 stores instructions for executing the container monitoring method.
[0225] The communication interface 138 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 13 and other devices or a communication network.
[0226] The container monitoring method disclosed in the above method embodiment may be applied to the processor 134, or implemented by the processor 134. The processor 134 may be an integrated circuit chip having a signal processor capability.
[0227] In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 134. The above processor 134 can be a general-purpose processor, including a CPU, a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete electron tubes or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to be executed, or the hardware and software modules in the decoding processor can be combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 136, and the processor 134 reads the information in the memory 136 and completes the steps of the above method in combination with its hardware.
[0228] In a possible implementation, the processor 134 may also be used to execute a container monitoring method. For a specific implementation, reference may be made to the embodiments provided by the above-mentioned container monitoring method, and the embodiments of the present application will not be described in detail herein.
[0229] In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.
[0230] The embodiment of the present application also provides a computing device cluster 14 for executing the above container monitoring method.
[0231] In one example, the computing device cluster 14 may include: Fig.11 The container monitoring device 11 shown includes a first monitoring module 111 and a second monitoring module 112 .
[0232] In another example, the computing device cluster 14 may include: Fig.12 The container monitoring system 12 shown includes a container monitoring device 11 and a cluster service device 121 .
[0233] In another example, Fig.14 As shown, the computing device cluster 14 includes at least one Fig.13The computing device 13 shown in FIG. 1 includes a bus 132, a processor 134, a memory 136, and a communication interface 138. The processor 134, the memory 136, and the communication interface 138 communicate with each other via the bus 132. The computing device 13 may be a server or a terminal device.
[0234] In a possible implementation, one or more computing devices in the computing device cluster 14 may be connected via a network, which may be a wide area network or a local area network. Fig.15 A possible implementation is shown. Fig.15 As shown, the two computing devices 13A and 13B are connected via a network. Specifically, the two computing devices are connected to the network via a communication interface in each computing device. In this type of possible implementation, the memory 136 in the computing device 13A stores instructions for executing the functions of the first monitoring module 111. At the same time, the memory 136 in the computing device 13B stores instructions for executing the functions of the second monitoring module 112.
[0235] Fig.15 The connection method between the computing device cluster 14 shown can be based on the container monitoring method provided by the present application. In the secure container scenario, it is necessary to deploy a second monitoring module on the first container, and collect the first operation data of the first container running application through data interaction between the first monitoring module and the second monitoring module. The first monitoring module and the second monitoring module can be deployed on different devices in the computing node. Therefore, it is considered that the functions implemented by the second monitoring module 112 are executed by the computing device 13B, and the functions implemented by the first monitoring module 111 are executed by the computing device 13A.
[0236] It should be understood that Fig.15 The functions of the computing device 13A shown in FIG. 1 may also be completed by multiple computing devices 13. Similarly, the functions of the computing device 13B may also be completed by multiple computing devices 13.
[0237] The present application also provides a computer program product including instructions. The computer program product may be a software or program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the above-mentioned container monitoring method.
[0238] For example, when the computer program product is run on at least one computing device, the at least one computing device is caused to execute Figure 5 The container monitoring method shown.
[0239] For another example, when the computer program product is run on at least one computing device, the at least one computing device executes Figure 7The container monitoring method shown.
[0240] The embodiment of the present application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be completed by a computer program to instruct the relevant hardware, and the program can be stored in the above computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be a terminal of any of the above embodiments, such as: an internal storage unit including a data transmission end and / or a data receiving end, such as a hard disk or memory of a terminal. The above computer-readable storage medium can also be an external storage device of the above terminal, such as a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (securedigital, SD) card, a flash card (flash card), etc. equipped on the above terminal. Further, the above computer-readable storage medium can also include both the internal storage unit of the above terminal and an external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above terminal. The above computer-readable storage medium can also be used to temporarily store data that has been output or is to be output.
[0241] It should be understood that the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the technical solution of this application are in compliance with relevant laws and regulations and do not violate public order and good morals. For example, in the technical solution of this application, the processing of user personal information is carried out with the authorization of the user, and the same description is not repeated here.
[0242] It should be noted that the terms "first" and "second" in the specification, claims and drawings of the present application are used to distinguish different objects rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or devices.
[0243] It should be understood that in the present application, "at least one (item)" means one or more, "more than one" means two or more, "at least two (items)" means two or three and more than three, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0244] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined based on A. It should also be understood that determining B based on A does not mean determining B only based on A, but B can also be determined based on A and / or other information. In addition, the "connection" that appears in the embodiments of the present application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and the embodiments of the present application do not impose any limitation on this.
[0245] Unless otherwise specified, the "transmission" (transmit / transmission) that appears in the embodiments of the present application refers to bidirectional transmission, including the actions of sending and / or receiving. Specifically, the "transmission" in the embodiments of the present application includes the sending of data, the receiving of data, or the sending of data and the receiving of data. In other words, the data transmission here includes uplink and / or downlink data transmission. Data may include channels and / or signals, uplink data transmission is uplink channel and / or uplink signal transmission, and downlink data transmission is downlink channel and / or downlink signal transmission.
[0246] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the grouping of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be grouped into different functional modules to complete all or part of the functions described above.
[0247] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the grouping of modules or units is only a logical function grouping, and there may be other grouping methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0248] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0249] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0250] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device, such as a single-chip microcomputer, chip, etc., or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media for storing program codes such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks or optical disks.
[0251] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A container monitoring method, characterized in that: The method is applied to a computing node, the computing node is deployed with a first container and a first monitoring module, the first container is deployed with a second monitoring module; the method comprises: The first monitoring module acquires first monitoring information; the first monitoring information is used to indicate an application that monitors the operation of the first container; The first monitoring module sends the first monitoring information to the second monitoring module; The second monitoring module samples first running data of the application running in the first container according to the first monitoring information, and sends the first running data to the first monitoring module; The first monitoring module feeds back a first monitoring result according to the first running data; the first monitoring result is used to indicate the running state of the application running in the first container.
2. The method according to claim 1, characterized in that The first monitoring information includes an application identifier and monitoring parameters; the application identifier is used to indicate the application.
3. The method according to claim 2, characterized in that The monitoring parameter includes at least one of a network parameter, a performance parameter or an operation parameter.
4. The method according to any one of claims 1 to 3, characterized in that The interface service module includes a correspondence between containers in the computing node and applications deployed on the containers; The first monitoring module obtains first monitoring information, including: The first monitoring module obtains the application identifier from the monitoring service module; The first monitoring module obtains container information corresponding to the application identifier from the interface service module according to the application identifier, wherein the container information includes a container type and a container identifier; The first monitoring module sends the first monitoring information to a second monitoring module corresponding to the container identifier.
5. The method according to claim 4, characterized in that The method further comprises: The first monitoring module sends a second monitoring module deployment request to the monitoring service module according to the container identifier; the second monitoring module deployment request is used to instruct the monitoring service module to deploy the second monitoring module in the first container corresponding to the container identifier.
6. The method according to claim 4, characterized in that The method further comprises: The first monitoring module obtains the monitoring parameters from the interface service module.
7. The method according to any one of claims 1 to 3, characterized in that The first monitoring module includes a correspondence between application identifiers and container identifiers; The first monitoring module sending the first monitoring information to the second monitoring module includes: The first monitoring module obtains the container identifier according to the application identifier in the first monitoring information and the correspondence between the application identifier and the container identifier; The first monitoring module sends the first monitoring information to a second monitoring module corresponding to the container identifier according to the container identifier.
8. The method according to claim 7, characterized in that The method further comprises: The first monitoring module receives a registration request sent by the second monitoring module, and establishes a correspondence between an application identifier and a container identifier; the registration request includes an application identifier and a container identifier of a container running corresponding to the second monitoring module.
9. The method according to any one of claims 1 to 8, characterized in that The second monitoring module samples first running data of the application running in the first container according to the first monitoring information, including: The second monitoring module obtains first operating data from the microkernel of the first container according to the monitoring parameters in the first monitoring information; the first operating data is used to indicate actual monitoring parameters of the first container during the execution of the application by the first container.
10. The method according to any one of claims 1 to 9, characterized in that The first monitoring module feeds back a first monitoring result according to the first operation data, including: The first monitoring module processes the first operating data to obtain actual monitoring parameters of the first container when the application is running; Comparing the actual monitoring parameter with a preset monitoring parameter threshold to obtain a running state of the application running in the first container; The first monitoring result is fed back to a monitoring service module according to the operating status and the actual monitoring parameters.
11. The method according to any one of claims 1 to 10, characterized in that The computing node further includes a second container, and the method further includes: The first monitoring module collects second operation data during the process of the second container running the application according to the monitoring parameters indicated by the second monitoring information; The first monitoring module feeds back a second monitoring result according to the second running data; the second monitoring result is used to indicate the running state of the application running in the second container.
12. A container monitoring device, characterized in that: The container monitoring device comprises: A first monitoring module is used to obtain first monitoring information and send the first monitoring information to a second monitoring module; the first monitoring is used to indicate an application for monitoring the running of the first container; The second monitoring module is used to sample first running data of the application running in the first container according to the first monitoring information, and send the first running data to the first monitoring module; The first monitoring module is further used to feed back a first monitoring result according to the first operating data; the first monitoring result is used to indicate the operating state of the first container during the running of the application.
13. The device according to claim 12, characterized in that The first monitoring information acquired by the first monitoring module includes an application identifier and monitoring parameters; the application identifier is used to indicate the application.
14. The device according to claim 13, characterized in that The monitoring parameters acquired by the first monitoring module include at least one of network parameters, performance parameters or operation parameters.
15. The device according to any one of claims 12 to 14, characterized in that The interface service module includes a correspondence between a container in a computing node and an application deployed on the container; the second monitoring module is deployed in the first container; The first monitoring module is used to obtain the application identifier from the monitoring service module, and obtain the container information corresponding to the application identifier from the interface service module according to the application identifier, wherein the container information includes a container type and a container identifier; The first monitoring module is used to send the first monitoring information to the second monitoring module corresponding to the container identifier.
16. The device according to claim 15, characterized in that The first monitoring module is further used to send a second monitoring module deployment request to the monitoring service module according to the container identifier; the second monitoring module deployment request is used to instruct the monitoring service module to deploy the second monitoring module in the first container.
17. The device according to claim 15, characterized in that The first monitoring module is further used to obtain the monitoring parameters from the interface service module.
18. The device according to any one of claims 12 to 14, characterized in that The first monitoring module is further configured to obtain a container identifier according to an application identifier in the first monitoring information and a correspondence between the application identifier and the container identifier, and send the first monitoring information to a second monitoring module corresponding to the container identifier according to the container identifier.
19. The device according to claim 18, characterized in that The second monitoring module is further used to send a registration request to the first monitoring module; the registration request includes an application identifier and a container identifier of the container running corresponding to the second monitoring module; The first monitoring module is further configured to receive the registration request sent by the first monitoring module and establish a corresponding relationship between the application identifier and the container identifier.
20. The device according to any one of claims 12 to 19, characterized in that The second monitoring module is used to obtain first operating data from the microkernel of the first container according to the monitoring parameters in the first monitoring information; the first operating data is used to indicate the actual monitoring parameters of the first container during the execution of the application by the first container.
21. The device according to any one of claims 12 to 20, characterized in that The first monitoring module is used to: Processing the first operating data to obtain actual monitoring parameters of the first container when the application is running; Comparing the actual monitoring parameter with a preset monitoring parameter threshold to obtain a running state of the application running in the first container; The first monitoring result is fed back to a monitoring service module according to the operating status and the actual monitoring parameters.
22. The device according to any one of claims 12 to 21, characterized in that The first monitoring module is further configured to collect second operation data of the second container during the operation of the application according to the monitoring parameters indicated by the second monitoring information, and to feed back a second monitoring result according to the second operation data; The second monitoring result is used to indicate a running status of the application running in the second container.
23. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 11.
24. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster is caused to perform the method according to any one of claims 1 to 11.
25. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device, the computing device performs the method as described in any one of 1 to 11.