Self-adaptive deployment method and system oriented to credential heterogeneous environment
By introducing an automated deployment engine and DAG dependency analysis algorithm in the heterogeneous environment of the Innovative Innovation, the problems of poor compatibility of multi-CPU architecture, complex software dependencies and high security configuration risks in the domestic environment are solved, and efficient automated deployment of domestic software in the heterogeneous CPU environment is achieved.
Patent Information
- Application Number
- CN202510551724.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-04-29
AI Technical Summary
In a domestic environment, the multi-CPU architecture has poor compatibility, complex software dependencies and high security configuration risks, resulting in the traditional deployment model being unable to meet the needs of rapid response.
An adaptive deployment method for information-innovation heterogeneous environments is proposed. Through automated deployment engines, hardware resource pools, domestic software standardized warehouses and system mirror warehouses, combined with DAG dependency analysis algorithms and Kahn topology sorting, automated deployment in heterogeneous CPU environment is realized.
It realizes one-click automation and efficient deployment of domestic software in heterogeneous CPU environment, solves dependency conflict problems, significantly improves deployment efficiency, eliminates manual operation errors, supports cross-architecture compatibility, and ensures network security and system stability.
Smart Images

Figure CN120104142A_ABST
Abstract
Description
Background Art
[0002] In the current development process of the information technology industry, the trend of domestic substitution is becoming increasingly significant. Great progress has been made in the fields of domestic operating systems, middleware and databases, and the industry has shown a high-speed growth trend, with an annual compound growth rate of up to 38.7%. Many companies are actively engaged in the application of domestic technology. However, in this process, their products face extremely complex domestic technology adaptation problems. The traditional construction and deployment model has exposed many drawbacks in the face of the rapid iteration of the domestic technology system. It can no longer meet the urgent needs of the company's products to respond quickly to the domestic environment. It is urgent to explore more efficient adaptation and delivery paths. Chinese patent application CN201110404908.5 discloses a method for semi-automatic batch deployment of heterogeneous cluster operating systems, which adopts a distributed center mirror server architecture, generates system images with the help of a sample machine, and accelerates the distribution of P2P images. Among them, heterogeneous nodes are installed through the network (ISO image), and homogeneous nodes are installed by file system replication. However, this solution lacks consideration of the uniqueness of domestic CPU architecture and does not address instruction set compatibility issues; the software installation process relies on manual operations, making it difficult to resolve domestic software version dependency conflicts; there are deficiencies in the security protection level, and it is impossible to achieve automatic configuration of firewall policies, making it difficult to cope with complex security challenges. Chinese patent application CN202011366095.0 discloses an intelligent deployment method for heterogeneous hybrid environments, which uses version control (Git / Svn) to manage configuration, uniformly manages hardware information, software dependencies and configuration items, and conducts intelligent environmental adaptation deployment based on the CART classification tree algorithm. However, this solution relies on foreign middleware such as Rancher / Nexus, which does not meet the requirements of independent and controllable development; the classification tree model needs to be pre-trained and it is difficult to keep up with the rapid update of domestic software; and the security protection capability is limited, only basic configuration management is implemented, which makes it difficult to deal with various security risks. Therefore, there is an urgent need for a new method for adaptive deployment of heterogeneous domestic CPUs in a trusted computing environment. Summary of the invention
[0003] In order to solve the above problems in the prior art, namely, the poor compatibility of multiple CPU architectures in the localized environment, the complex software dependencies and the high security configuration risk, the first aspect of the present invention proposes an adaptive deployment method for a heterogeneous environment of information innovation, the method comprising the following steps: S1. Obtain task instructions, create a new target task in a pre-built automated deployment engine, and define the basic metadata of the environment for deploying the target task; the automated deployment engine includes a hardware resource pool, a domestic software standardized warehouse, and a system image warehouse; S2. Analyze the target task to obtain the hardware information template and key hardware parameters; S3. Based on the key hardware parameters, configure the virtual machine to be built, dynamically match the CPU architecture and OS in the system image repository, and generate a candidate list of CPU architectures and OSs that are architecture-compatible; S4. Determine the target CPU architecture and target OS, pull the image adapted to the target CPU architecture from the system image repository to the local host of the host machine, and perform a security check; S5. Generate a virtual machine startup command according to the hardware information template, send it to the host machine for execution, and perform a secondary security check; S6. Inject the IP address information in the environment basic metadata into the network card configuration file and restart the network card; S7. Identify the firewall type of the target system based on the firewall probe, generate an adaptive network security policy according to the identification result, obtain a network security configuration file and load it; S8. After the network security configuration file is loaded, pull the target software and its dependency configuration file from the domestic software standardization repository to the virtual machine, extract its dependencies and version constraints, and generate a topological sorting result based on the DAG-based dependency parsing algorithm; S9. Execute the installation in sequence according to the topological sorting result to realize the automated deployment of the application software.
[0004] In some preferred embodiments, the environment basic metadata includes a project number, a deployment type, CPU information, CPU cores, memory specifications, storage capacity, operating system name, system version, IP address information, firewall whitelist, and a list of pre-installed software.
[0005] In some preferred embodiments, the method for obtaining the hardware information template and key hardware parameters is as follows: Assemble the environment basic metadata of the target task into a hardware information template, and parse the hardware information template to obtain key hardware parameters including processor architecture, memory capacity, number of CPU cores, and storage space.
[0006] In some preferred embodiments, during the process of dynamically matching the CPU architecture and OS, based on the load status of the resource pool, perform a dynamic capacity assessment of the CPU: If the average CPU usage rate continuously ≥ M% and < N%, trigger a mild alarm and prompt an expansion suggestion; if the CPU usage rate ≥ N% or the single-core peak ≥ S%, trigger the termination of the build and give an alarm; where M < N < S.
[0007] In some preferred embodiments, the method for performing the security check is as follows: When pulling an image, the pre-stored hash value is read from the metadata file and compared with the real-time hash value of the image after transmission; if the verification fails, automatic retransmission or alarm is triggered; The automatic retransmission is executed no more than 3 times.
[0008] In some preferred implementations, a secondary security check is performed, and the method is as follows: Before starting the virtual machine, verify the original hash value of the image file and compare it with the pre-stored hash value in the metadata. If the hash values are consistent, start the virtual machine. Otherwise, terminate the deployment and mark the image file as untrustworthy. When the execution is completed, the system prompts the user to confirm.
[0009] In some preferred implementations, the method for generating an adaptive network security strategy is as follows: The firewall service currently used by the host is identified through probe technology, and the predefined security policy template is called according to the identification result. The placeholders in the template are automatically replaced to generate specific configuration instructions. Then, the execution of the security policy is driven through SSH, and the validity is verified. The command execution and security parameter appending are dynamically generated according to the needs.
[0010] In some preferred embodiments, if the identification result is that multiple firewall services are active at the same time, the highest priority firewall is selected as the main firewall, other firewall services are automatically disabled, and a firewall service conflict report is generated and pushed to the management interface to prompt the user for confirmation; if the user confirms, the historical rules of other firewalls are migrated to the main firewall.
[0011] In some preferred implementations, a DAG-based dependency parsing algorithm generates a topological sorting result, and the method is: A. Create a DAG node and verify whether the software package supports the target CPU architecture; B. Parsing dependencies based on the extracted dependencies and version constraints, and building a DAG dependency graph; C. Use depth-first search to traverse the DAG dependency graph and detect whether there is a circular dependency: If it does not exist, jump to step D; Otherwise, search for low-version dependencies from the domestic software standard repository for replacement, and then execute step A; if no version is found, generate a circular dependency report containing conflicting paths and recommended versions and push for manual decision; D. Check whether there is a version conflict. If not, jump to step E; otherwise, search for a compatible version or a recommended equivalent version from the domestic software standardization warehouse first, replace it, and then execute step A; if replacement is not possible, generate a conflict report for manual processing; E. Generate a topological sorting sequence based on the Kahn algorithm and mark the node groups without direct dependencies as parallel installable.
[0012] The second aspect of the present invention proposes an adaptive deployment system for a heterogeneous information innovation environment, comprising: The automated deployment engine is configured to generate a virtual machine startup command based on the hardware information template and send it to the host machine for execution; it is also configured to inject the IP address information in the environment basic metadata into the network card configuration file and restart the network card; it is also configured to perform installation in sequence according to the topological sorting result to realize the automated deployment of the application system; the automated deployment engine includes a hardware resource pool, a domestic software standardized warehouse and a system image warehouse; A hardware parameter configuration / parsing module is configured to obtain task instructions, create a new target task in a pre-built automated deployment engine, and define the basic metadata of the environment for deploying the target task, thereby obtaining a hardware information template and key hardware parameters; A cross-platform image generation module is configured to dynamically match the CPU architecture and OS in the system image warehouse based on the key hardware parameters, and generate a candidate list of CPU architectures and OSs that are compatible with the architecture; it is also configured to parse the device IP information of the host machine according to the target CPU architecture and the target OS, and pull the image adapted to the target CPU architecture from the system image warehouse to the local host machine; it is also configured to pull the target software and dependency configuration files from the domestic software standardization warehouse; A security check module is configured to perform a security check when pulling an image; and is also configured to perform a secondary security check before executing a virtual machine startup command; A network security module is configured to execute a firewall probe, identify the firewall type of the target system, generate an adaptive network security policy based on the identification result, obtain a security configuration file and load it; The topological sorting generation module is configured to extract the dependencies and version constraints of the target software and dependency configuration files, abstract the software packages into DAG nodes, and generate topological sorting results based on the DAG dependency resolution algorithm.
[0013] Beneficial effects of the present invention: (1) This method builds a multi-architecture automatic deployment engine for the hardware abstraction layer through a hardware resource pool, a multi-architecture operating system image library, and a standardized software warehouse. It combines the DAG dependency parsing algorithm with the Kahn topological sorting to optimize the installation order, and achieves one-click automated and efficient deployment of domestic software such as databases and middleware in a heterogeneous CPU environment, solving the problem of dependency conflicts; significantly improving deployment efficiency, eliminating manual operation errors, and supporting cross-architecture compatibility; (2) Use probe + rule engine to dynamically adapt firewall policies to ensure compliance with the security requirements of Information Security Protection 2.0. Support dynamic adaptation of mainstream firewall tools such as firewalld, ufw, iptables, etc. to achieve rapid deployment of firewall policies. It can automatically adjust policies according to changes in the network environment to ensure the network security of the system. (3) Through hash verification and security policy automation configuration, the SHA-256 hash verification algorithm is used to ensure the security and consistency of the image during the generation, transmission and use of the image, prevent the image from being tampered with or damaged, ensure the stable operation of the system, and provide solid support for the trust innovation ecosystem; (4) The environment configuration of domestic systems is simplified by dynamically generating configuration files through preset templates. The standardized software repository built covers basic software. The dependencies and compatibility constraints of software packages are defined through depends.json. The dependency parsing algorithm of DAG is combined to automatically generate directed acyclic graphs. The Kahn algorithm is combined to optimize the installation sequence, solve the problem of multi-level nested dependencies, automatically generate conflict-free installation sequences, optimize dynamic dependency parsing, and reduce repeated debugging caused by manual intervention. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings: Figure 1 It is a flow chart of an adaptive deployment method for a heterogeneous information innovation environment in an embodiment of the present invention; Figure 2 is a flow chart of an adaptive network security policy generation strategy in an embodiment of the present invention; Figure 3 is a schematic diagram of a security policy template library in an embodiment of the present invention; Figure 4 is a flowchart of a system for pulling images from an image library and a hash verification flowchart in an embodiment of the present invention; Figure 5 It is a flowchart of software automatic deployment in an embodiment of the present invention. DETAILED DESCRIPTION
[0015] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It is also necessary to explain that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0016] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0017] Aiming at the problems of poor compatibility of multiple CPU architectures, complex software dependencies, and high security configuration risks in the domestic environment, the present invention proposes an adaptive deployment method for the heterogeneous environment of information creation based on dynamic dependency analysis and adaptive strategies. By building a hardware resource pool, a multi-architecture operating system image library, and a standardized software warehouse, the DAG dependency analysis algorithm and the Kahn topological sorting optimization installation sequence are combined to achieve one-click automated and efficient deployment of domestic software such as databases and middleware in a heterogeneous CPU environment. Compatibility with multiple domestic CPU architectures is achieved, and one-click automated deployment of domestic operating systems, databases, middleware, and other software is achieved, which improves deployment efficiency, reduces deployment difficulty, and builds a safe, reliable, and universal automated deployment solution to help promote the smooth application of domestic technologies.
[0018] In order to more clearly illustrate the adaptive deployment method for the heterogeneous environment of the present invention, the following is combined with Figure 1-5 Each step in the embodiment of the present invention is described in detail.
[0019] The first embodiment of the present invention provides an adaptive deployment method for a heterogeneous information innovation environment, including steps S100 to S600, each of which is described in detail as follows: S100, obtaining task instructions, creating a new target task in a pre-built automated deployment engine, and defining the basic metadata of the environment for deploying the target task, and finally assembling this information into a hardware information configuration template; the automated deployment engine includes a hardware resource pool, a domestic software standardized warehouse, and a system image warehouse.
[0020] Preferably, the basic environment metadata includes project number, deployment type, CPU information, CPU core, memory specification, storage capacity, operating system name, system version, IP address information, firewall whitelist and pre-installed software list.
[0021] Preferably, building an automated deployment engine includes separately building a basic domestic hardware pool, a storage pool, a domestic software standardized warehouse, and a system image warehouse.
[0022] In this embodiment, a basic domestic hardware pool and storage pool are constructed, and the domestic hardware CPU, memory, storage, and network are virtualized by using the bare metal virtualization technology QEMU-KVM. For different CPU architectures (such as LoongArch, the KVM extension module needs to be enabled), the corresponding virtualization driver is dynamically loaded; then the architecture, memory, number of cores, and storage capacity information are recorded, and the recorded information can be dynamically adjusted according to the actual information of the host hardware resource pool.
[0023] In this embodiment, a standardized warehouse for domestic software is built, covering the full-stack software ecosystem of mainstream domestic CPU architectures, and a layered architecture design is used to achieve unified management and scheduling of domestic components: The operating system layer integrates mainstream domestic operating system distributions to form a multi-architecture compatible system including domestic OS, supporting mainstream instruction sets such as C86 / ARM / SW64, and ensuring cross-platform deployment capabilities. The database layer provides full-scenario solutions for domestic databases, including transactional databases and analytical databases. The middleware layer covers enterprise-level application support platforms. In addition, out-of-the-box configuration templates are provided, including pre-installed software installation addresses, configuration files, pre-installed parameters, and default port information. The dependency environment layer builds a standardized development tool chain including gcc / g++, supports C / C++ compilation, glibc compatibility layer, Java JDK, etc. By covering the complete basic software "operating system-database-middleware" technology stack, domestic ecological integration is achieved.
[0024] In this embodiment, the mainstream domestic CPU architecture is any one of C86 / ARM / MIPS / LoongArch / SW64.
[0025] The standardized software warehouse built covers basic software (database, middleware, dependent environment, etc.), defines the software package dependencies and compatibility constraints through depends.json, combines the DAG dependency parsing algorithm, automatically generates a directed acyclic graph, and combines the Kahn algorithm to optimize the installation sequence and solve the multi-level nested dependency problem. The layered architecture design is used to achieve unified management and automated deployment of domestic components.
[0026] In this embodiment, a system image warehouse is built, and the system image warehouse stores system templates in RAW format (supporting fast cloning and bare metal performance), mainly including operating system basic templates and application platform combination templates. Users can check and use them as needed to achieve the purpose of rapid deployment. After the image is built, its SHA-256 hash value is immediately calculated, and the hash value is written to the metadata file (metadata.json), which is stored in the warehouse synchronously with the image.
[0027] Further preferably, in this embodiment, the storage capacity threshold is preset according to actual business needs.
[0028] S200: According to the task information submitted by the user, the obtained hardware information configuration template is parsed, and the obtained key hardware parameters are parsed; the key hardware parameters include: Processor architecture, memory capacity, number of CPU cores, and storage space.
[0029] The hardware abstraction layer is used to decouple the environment configuration from the physical device. That is, the hardware parameters are defined as template data. The hardware is dynamically adapted according to the template data during deployment, rather than hard-coded into a server. The same template can be reused across different domestic CPUs. Ultimately, the environment configuration and physical device are decoupled to ensure the consistency of the environment configuration.
[0030] During the parsing process, the processor architecture information is first filtered and compared with the host information in the hardware pool to obtain the IP address and configuration information of the target host. The virtual machine hardware parameters are compared with the available resources of the host to determine whether they have not exceeded and reached the critical value. Otherwise, the host cannot meet the virtual machine requirements.
[0031] S300. Based on the key hardware parameters, the virtual machine to be built is configured, and the domestic CPU and the domestic operating system are dynamically matched according to the hardware parameters in the system image warehouse, and a candidate list of architecture-compatible CPU architectures and OS is generated for user selection.
[0032] Preferably, in this embodiment, during the process of dynamically matching the CPU architecture and the OS, the CPU capacity is dynamically evaluated based on the resource pool load status, and a graded alarm is triggered if the resources are insufficient: If the average CPU usage rate is continuously ≥70% and <80%, a minor alarm is triggered, and a capacity expansion suggestion is prompted. If the CPU usage rate is ≥80% or the single-core peak value is ≥95%, the build is terminated and an alarm is triggered.
[0033] S400, determine the target CPU architecture and target OS, parse the device IP information of the host machine, pull the image adapted to the target CPU architecture from the system image repository to the local host machine, and perform security verification.
[0034] Preferably, in this embodiment, according to the CPU architecture selected by the user, the host device IP address is parsed through the resource scheduling module to ensure that the target host has virtualization support for the corresponding CPU instruction set (such as the ARM host needs to start the KVM-RAM extension). The bare metal level deployment efficiency is achieved through the KVM virtualization driver layer (QEMU-KVM technology), and the rapid installation and deployment of the operating system is achieved.
[0035] Preferably, in this embodiment, according to the operating system selected by the user, a RAW format image adapted to the target CPU architecture is pulled from a preset operating system image repository to the local host machine.
[0036] Pre-installing domestic operating systems and drivers through the operating system image warehouse improves the efficiency of software installation. When a virtual machine needs to be created, the current host machine will be matched according to the configuration and requirements of the target virtual machine, and then the RAW image of the target virtual machine will be pulled to the host machine, and the virtual machine will be started; the host machine's virtualization software will allocate corresponding resources to the virtual machine according to the storage location and related configuration information of the image on the host machine, and load the operating system and related software in the image into the virtual machine, thereby completing the startup and initialization of the virtual machine.
[0037] In some preferred implementations, when pulling an image, a security check is performed, and the method is as follows: When pulling an image, the pre-stored hash value is read from the metadata file and compared with the real-time hash value of the image after transmission. If the verification succeeds, the automatic deployment process continues; if the verification fails, automatic retransmission or alarm is triggered; The automatic retransmission is executed no more than 3 times.
[0038] S500. Generate a virtual machine startup command based on the hardware information template and send it to the host machine for execution; before starting the virtual machine, verify the original hash value of the image file twice and compare it with the pre-stored hash value in the metadata. If the hash values are consistent, start the virtual machine; otherwise, terminate the deployment and mark the image file as "untrusted". The execution ends and the system prompts the user to confirm.
[0039] S600, inject the IP address information in the environment basic metadata into the network card configuration file, and restart the network card, the method is: Use virt-customize to inject the preset IP information into the network card configuration file, then restart the network card, and check whether you can PING the host machine based on the IP address information (IP / network card / DNS). If you cannot PING, roll back the operation.
[0040] S700, based on the firewall probe, identifies the firewall type of the target system, calls the predefined security policy template according to the identification result, and dynamically generates an adaptive network security policy that complies with the requirements of Information Security Technology 2.0 and Information Security Innovation.
[0041] Preferably, the method for generating an adaptive network security strategy is: The firewall service currently used by the host is identified through probe technology, and the predefined security policy template is called according to the identification result. The placeholders in the template are automatically replaced to generate specific configuration instructions. Then, the execution of the security policy is driven by SSH and the effectiveness is verified. The configuration rule base complies with the "Information Security Technology-Basic Requirements for Network Security Level Protection" (GB / T 22239-2019), that is, the regulations of Level Protection Technology 2.0 and the adaptation requirements in the information innovation environment, avoiding the risks of manual configuration.
[0042] Further preferably, in this embodiment, if the identification result is that multiple firewall services are active at the same time, the highest priority firewall is selected as the main firewall, other firewall services are automatically disabled, and a firewall service conflict report is generated and pushed to the management interface to prompt the user for confirmation; if the user confirms, the historical rules of other firewalls are migrated to the main firewall.
[0043] Further preferably, in this embodiment, the method for identifying the firewall service currently used by the host machine is: Use the firewall status detection command (such as: systemctl is-active firewalld> / dev / null 2>&1&&echo "firewalld") to detect the firewall service status by executing system commands. The matching priority logic detects in the order of firewalld->ufw->iptables and matches the first active firewall service, such as Figure 3 shown.
[0044] The firewall policy generation mechanism of probe + rule engine is adopted, which supports dynamic adaptation of mainstream firewall tools such as firewalld, ufw, iptables, etc., and realizes rapid deployment of firewall policies. The policy can automatically adjust the policy according to the changes in the network environment to ensure the network security of the system.
[0045] S800, pull the target software and dependency configuration file depends.json from the domestic software standard warehouse, extract its dependencies and version constraints, and generate topological sorting results based on the DAG dependency resolution algorithm.
[0046] Preferably, a DAG-based dependency parsing algorithm generates a topological sorting result, and the method is: A. Create a DAG node and verify whether the software package supports the target CPU architecture. If the dependency only supports the X86 architecture, an alarm is triggered and the incompatible node is excluded; B. Based on the extracted dependencies and version constraints, the dependencies are parsed, and a DAG dependency graph is constructed to map each software package (such as A, B) as a node, annotate the name, version and architecture information, and create directed edges based on the dependencies (if A depends on B, an edge from A to B is generated); C. Use depth-first search to traverse the DAG dependency graph and detect whether there is a circular dependency (such as A→B→A): If it does not exist, jump to step D; Otherwise, search for low-version dependencies from the domestic software standard repository for replacement, and then execute step A; if no version is found, generate a circular dependency report containing conflicting paths and recommended versions and push for manual decision; D. Check whether there is a version conflict (for example, A requires glibc ≥ 2.17, and B requires glibc < 2.0): If it does not exist, jump to step E; Otherwise, search for compatible versions or recommended equivalent versions from the domestic software standardization warehouse first, replace them, and then execute step A; if replacement is not possible, generate a conflict report for manual processing; E. Generate a topological sorting sequence based on the Kahn algorithm and mark the node groups without direct dependencies as parallel installable.
[0047] The DAG-based dependency resolution algorithm (Kahn topological sorting) automatically generates a conflict-free installation sequence, optimizes dynamic dependency resolution, and reduces repeated debugging caused by manual intervention.
[0048] S900, perform installation in order according to the topological sorting results, and use RPM / DPKG commands to install dependencies; assign components marked as parallel to independent threads for concurrent execution, and limit the maximum number of parallel operations through the thread pool (logical CPU number). Monitor the installation status in real time during the deployment process. If a node fails (such as missing dependencies), immediately interrupt the process and roll back the installed components; verify the validity and integrity of the software after the installation is complete.
[0049] Preferably, after all nodes are successfully installed, the authorization file is configured, the authorization certificate file is deployed to the installation root directory, and finally the service startup verification is performed and uniformly fed back to the user; after all is completed, the system interface prompts "Deployment Completed" and generates a deployment report containing detailed logs, recording the installation time, parallel efficiency and abnormal events.
[0050] Preferably, before installation, the environment is verified, and a multi-dimensional environment detection is performed on the target host through a preset verification module, including hardware indicators such as memory capacity and disk space.
[0051] Although the various steps in the above embodiment are described in the above-mentioned order, those skilled in the art can understand that in order to achieve the effect of this embodiment, different steps do not have to be executed in such an order. They can be executed simultaneously (in parallel) or in a reverse order. These simple changes are within the scope of protection of the present invention.
[0052] A second embodiment of the present invention provides an adaptive deployment system for a heterogeneous information and communication environment, including: The automated deployment engine is configured to generate a virtual machine startup command based on the hardware information template and send it to the host machine for execution; it is also configured to inject the IP address information in the environment basic metadata into the network card configuration file and restart the network card; it is also configured to perform installation in sequence according to the topological sorting result to realize the automated deployment of the application system; the automated deployment engine includes a hardware resource pool, a domestic software standardized warehouse and a system image warehouse; A hardware parameter configuration / parsing module is configured to obtain task instructions, create a new target task in a pre-built automated deployment engine, and define the basic metadata of the environment for deploying the target task, thereby obtaining a hardware information template and key hardware parameters; A cross-platform image generation module is configured to dynamically match the CPU architecture and OS in the system image warehouse based on the key hardware parameters, and generate a candidate list of CPU architectures and OSs that are compatible with the architecture; it is also configured to parse the device IP information of the host machine according to the target CPU architecture and the target OS, and pull the image adapted to the target CPU architecture from the system image warehouse to the local host machine; it is also configured to pull the target software and dependency configuration files from the domestic software standardization warehouse; A security check module is configured to perform a security check when pulling an image; and is also configured to perform a secondary security check before executing a virtual machine startup command; A network security module is configured to execute a firewall probe, identify the firewall type of the target system, call a predefined security policy template based on the identification result, and generate an adaptive network security policy; The topological sorting generation module is configured to extract the dependencies and version constraints of the target software and dependency configuration files, abstract the software packages into DAG nodes, and generate topological sorting results based on the DAG dependency resolution algorithm.
[0053] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process and related instructions of the system described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0054] It should be noted that the above embodiment provides an adaptive deployment system for heterogeneous environments of information and entrepreneurship, and only uses the division of the above functional modules as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the modules or steps in the embodiments of the present invention can be decomposed or combined. For example, the modules in the above embodiments can be combined into one module, or further divided into multiple sub-modules to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present invention are only for distinguishing the modules or steps, and are not regarded as improper limitations of the present invention.
[0055] An electronic device according to a third embodiment of the present invention includes: at least one processor; and a memory communicatively connected to at least one of the processors; wherein, The memory stores instructions that can be executed by the processor, and the instructions are used to be executed by the processor to implement the above-mentioned adaptive deployment method for heterogeneous environments of information and innovation.
[0056] A computer-readable storage medium according to the fourth embodiment of the present invention stores computer instructions, and the computer instructions are used to be executed by the computer to implement the above-mentioned adaptive deployment method for heterogeneous environments of information and innovation.
[0057] Technicians in the relevant technical field can clearly understand that, for the convenience and brevity of description, the specific working process and related instructions of the electronic device and computer-readable storage medium described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0058] Those skilled in the art should be able to appreciate that the modules and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two, and the programs corresponding to the software modules and method steps can be placed in random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the technical field. In order to clearly illustrate the interchangeability of electronic hardware and software, the composition and steps of each example have been generally described in the above description according to the function. Whether these functions are performed in electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0059] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0060] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0061] The terms "first", "second", etc. are used to distinguish similar objects rather than to describe or indicate a particular order or sequence.
[0062] The term "comprise" or any other similar term is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus / device that includes a list of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, article, or apparatus / device.
[0063] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
Claims
1. An adaptive deployment method for heterogeneous environments of information technology, characterized in that: It includes the following steps: S1. Obtain a task instruction, create a target task in a pre-built automated deployment engine, and define the environmental basic metadata for deploying the target task; the automated deployment engine includes a hardware resource pool, a domestic software standardization repository, and a system image repository; S2. Parse the target task to obtain a hardware information template and key hardware parameters; S3. Based on the key hardware parameters, configure the virtual machine to be built, dynamically match the CPU architecture and OS in the system image repository, and generate a candidate list of CPU architectures and OSs that are architecture-compatible; S4. Determine the target CPU architecture and target OS, pull the image adapted to the target CPU architecture from the system image repository to the local host of the host, and perform a security check; S5. Generate a virtual machine startup command according to the hardware information template, send it to the host for execution, and perform a secondary security check; S6. Inject the IP address information in the environmental basic metadata into the network card configuration file and restart the network card; S7. Identify the firewall type of the target system based on a firewall probe, generate an adaptive network security policy according to the identification result, obtain a security configuration file and load it; S8. After the security configuration file is loaded, pull the target software and its dependent configuration files from the domestic software standardization repository to the virtual machine, extract its dependencies and version constraints, and generate a topological sorting result based on the DAG-based dependency parsing algorithm; S9. Perform installations in sequence according to the topological sorting result to achieve the automated deployment of application software.
2. According to claim 1, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The environmental basic metadata includes a project number, a deployment type, CPU information, CPU cores, memory specifications, storage capacity, operating system name, system version, IP address information, firewall whitelist, and a list of pre-installed software.
3. According to claim 2, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The method for obtaining the hardware information template and key hardware parameters is as follows: Assemble the environmental basic metadata of the target task into a hardware information template, and parse the hardware information template to obtain key hardware parameters including the processor architecture, memory capacity, number of CPU cores, and storage space.
4. According to claim 1, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: During the process of dynamically matching the CPU architecture and OS, perform a dynamic capacity assessment of the CPU based on the load status of the resource pool: If the average CPU usage rate continuously ≥ M% and < N%, trigger a mild alarm and prompt a capacity expansion suggestion; if the CPU usage rate ≥ N% or the single-core peak ≥ S%, trigger the termination of the build and give an alarm; where M < N < S.
5. According to claim 2, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The method for performing a security check is as follows: When pulling the image, read the pre-stored hash value from the metadata file and compare it with the real-time hash value of the transferred image; if the check fails, trigger an automatic retransmission or give an alarm; where the number of executions of the automatic retransmission does not exceed 3 times.
6. According to claim 5, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The method for performing a secondary security check is as follows: Before starting the virtual machine, check the original hash value of the image file and compare it with the pre-stored hash value in the metadata. If the hash values are the same, start the virtual machine; otherwise, terminate the deployment, mark the image file as untrusted, end the execution, and the system will pop up a window to remind the user to confirm.
7. According to claim 1, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The method for generating an adaptive network security policy is as follows: The firewall service currently used by the host is identified through probe technology, and the predefined security policy template is called according to the identification result. The placeholders in the template are automatically replaced to generate specific configuration instructions. Then, the execution of the security policy is driven through SSH, and the validity is verified. The command execution and security parameter appending are dynamically generated according to the needs.
8. According to claim 7, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: If the identification result shows that multiple firewall services are active at the same time, the highest priority firewall is selected as the main firewall, other firewall services are automatically disabled, and a firewall service conflict report is generated and pushed to the management interface to prompt the user for confirmation; If the user confirms that the rule is passed, the historical rules of other firewalls will be migrated to the main firewall.
9. According to claim 1, the adaptive deployment method for heterogeneous environments of information innovation is characterized in that: The DAG-based dependency parsing algorithm generates a topological sorting result, and the method is as follows: A. Create a DAG node and verify whether the software package supports the target CPU architecture; B. Parsing dependencies based on the extracted dependencies and version constraints, and building a DAG dependency graph; C. Use depth-first search to traverse the DAG dependency graph and detect whether there is a circular dependency: If it does not exist, jump to step D; Otherwise, search for low-version dependencies from the domestic software standard repository for replacement, and then execute step A; if no version is found, generate a circular dependency report containing conflicting paths and recommended versions and push for manual decision; D. Check whether there is a version conflict. If not, jump to step E; otherwise, search for a compatible version or a recommended equivalent version from the domestic software standardization warehouse first, replace it, and then execute step A; if replacement is not possible, generate a conflict report for manual processing; E. Generate a topological sorting sequence based on the Kahn algorithm and mark the node groups without direct dependencies as parallel installable.
10. An adaptive deployment system for a heterogeneous environment of information and entrepreneurship, according to an adaptive deployment method for a heterogeneous environment of information and entrepreneurship according to any one of claims 1 to 9, characterized in that: The system includes: A hardware parameter configuration / parsing module is configured to obtain task instructions, create a new target task in a pre-built automated deployment engine, and define the basic metadata of the environment for deploying the target task, thereby obtaining a hardware information template and key hardware parameters; The automated deployment engine is configured to generate a virtual machine startup command based on the hardware information template and send it to the host machine for execution; inject the IP address information in the environment basic metadata into the network card configuration file and restart the network card; and is also configured to perform installation in sequence according to the topological sorting result to realize the automated deployment of the application system; the automated deployment engine includes a hardware resource pool, a domestic software standardized warehouse, and a system image warehouse; The cross-platform image generation module is configured to dynamically match the CPU architecture and OS in the system image warehouse based on the key hardware parameters, and generate a candidate list of CPU architectures and OSs that are compatible with the architecture; according to the target CPU architecture and the target OS, parse the device IP information of the host machine, and pull the image adapted to the target CPU architecture from the system image warehouse to the local host machine; and is also configured to pull the target software and dependency configuration files from the domestic software standardization warehouse; A security check module is configured to perform a security check when pulling an image; and is also configured to perform a secondary security check before executing a virtual machine startup command; A network security module is configured to execute a firewall probe, identify the firewall type of the target system, generate an adaptive network security policy based on the identification result, obtain a security configuration file and load it; The topological sorting generation module is configured to extract the dependencies and version constraints of the target software and dependency configuration files, abstract the software packages into DAG nodes, and generate topological sorting results based on the DAG dependency resolution algorithm.
Citation Information
Patent Citations
A method for semi-automatic batch deployment of heterogeneous cluster operating systems
CN102497408B
A cross-platform cross-commercial autonomous environment complex giant information system hybrid deployment system
CN109814878A
Container and cloud platform-based all-localization fusion cloud platform management method and system
CN109889480A
Intelligent deployment method for heterogeneous hybrid environment
CN112416369A
Method and system for realizing auditing firewall probe SDK (Software Development Kit)
CN115632861A
Cited By
Cloud code deployment system
CN120669994A
Heterogeneous computing task construction method and system based on low-code platform
CN120743260A
Database installation and deployment method based on MCP protocol
CN120743299A
Data processing method and electronic equipment
CN120910392A
Method and system for cloud platform to automatically adapt to computing node, terminal and storage medium
CN121173664A