Container creation method and device, medium, electronic equipment and computer program product
By reusing the recycled containers in the container pool, the problem of resource waste and waiting time during burst traffic is solved, rapid container creation and efficient resource utilization are achieved, and service stability is improved.
Patent Information
- Application Number
- CN202510300699.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-06
AI Technical Summary
When the number of user visits increases sharply, it is difficult for the existing technology to quickly deal with burst traffic, resulting in waste of resources and increased waiting time.
By retaining recycled containers in the container pool and reusing component data in these containers that are not associated with business logic during container creation, avoiding frequent creation and destruction of containers, improving container creation efficiency.
It realizes rapid creation of containers in the case of burst traffic, reducing resource waste and user waiting time, and effectively reducing the utilization of cluster resources and improving service stability.
Smart Images

Figure CN120104256A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular, to a container creation method, device, medium, electronic device, and computer program product. Background Art
[0002] With the development of computer technology, the business traffic in user-oriented applications is difficult to predict. For example, the occurrence of a hot event may cause the user traffic to increase by more than a hundred times in an instant. Preparing a large amount of resources in advance to deal with sudden business traffic will result in a serious waste of resources. Therefore, when the user traffic increases sharply, how to quickly apply resources to deal with these sudden traffic has become an urgent problem to be solved. Summary of the invention
[0003] This summary is provided to introduce concepts in a brief form that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0004] In a first aspect, the present disclosure provides a container creation method, the method comprising: In response to receiving a container creation request of the first service, obtaining a first container from a container pool, wherein the container pool includes a container obtained by recycling a container created by the second service, and component data in the container that is not logically associated with the second service is retained; Based on the image file of the first business, obtaining a root file system corresponding to the first business; A target container required by the first service is created based on the first container and the root file system.
[0005] In a second aspect, the present disclosure provides a container creation device, the device comprising: an acquisition module, configured to acquire a first container from a container pool in response to receiving a container creation request of a first service, wherein the container pool includes a container obtained by recycling a container created by a second service, and component data in the container that is not logically associated with the second service is retained; A determination module, configured to obtain a root file system corresponding to the first service based on the image file of the first service; A creation module is used to create a target container required by the first service based on the first container and the root file system.
[0006] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in the first aspect when the computer program is executed by a processing device.
[0007] In a fourth aspect, the present disclosure provides an electronic device, including: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method described in the first aspect.
[0008] In a fifth aspect, the present disclosure provides a computer program product, including a computer program, which implements the steps of the method described in the first aspect when executed by a processor.
[0009] In the above technical solution, the created container is not directly destroyed when it is recycled, and the component data in the container that is not related to the logic of the business is retained. For example, namespace destruction usually consumes a lot of CPU resources, so the solution of the present disclosure can avoid the large consumption of resources caused by frequent creation and destruction of containers, and can avoid repeated allocation of resources to improve the efficiency of container creation. In addition, in the present disclosure, containers can be created based on containers in the container pool, so that the reuse of component data in the container that is not related to the logic of the business can be achieved, and the efficiency of container creation can be further improved, so that when the business traffic increases sharply, the creation of the container can be completed quickly and accurately, and the response to the burst traffic can be achieved, and the user access waiting time is reduced. In addition, the container pool maintains the recycled containers. Compared with the related art of pre-starting a certain number of instances with different resource specifications and language runtimes in the cluster to establish a container pool, the solution in the present disclosure can effectively reduce the occupation of the CPU, memory, and storage resources of the cluster, reduce the difficulty of maintaining the container pool, and improve the service stability when facing burst traffic loads.
[0010] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1 The present invention is a flowchart of a method for creating a container according to an embodiment of the present invention.
[0012] Figure 2 It is a schematic diagram of container recycling and container reuse in a container creation process provided according to an embodiment of the present disclosure.
[0013] Figure 3The present invention is a block diagram of a container creation device provided according to an embodiment of the present invention.
[0014] Figure 4 A schematic diagram of the structure of an electronic device suitable for implementing the embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0015] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0016] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0017] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0019] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0021] It is understandable that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, scope of use, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0022] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present disclosure according to the prompt message.
[0023] As an optional but non-limiting implementation, in response to receiving an active request from the user, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0024] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet the relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0025] At the same time, it is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0026] The applicant has found that FaaS (Function as a Service) provides a cloud computing programming model. Relying on FaaS, developers only need to upload business code and perform simple resource configuration to quickly build and deploy services. However, while the stateless function programming of FaaS's Serverless computing brings high elasticity and flexibility, it also leads to the inevitable cold start problem. When a request arrives, if there is no available instance, a new instance needs to be started from scratch to process the request (i.e., cold start). When a cold start occurs, the Serverless platform needs to perform a series of operations such as instance scheduling, image distribution, container creation, and process startup. The delay caused by this process can usually reach hundreds of milliseconds to seconds, which is very unfriendly to businesses with short request processing times. Based on this, the present disclosure provides the following embodiments.
[0027] Figure 1 As shown, it is a flowchart of a container creation method provided according to an embodiment of the present disclosure, such as Figure 1 As shown, the method may include: In step 11, in response to receiving a container creation request of a first business, a first container is obtained from a container pool, wherein the container pool includes a container obtained by recycling a container created by a second business, and component data in the container that is not logically associated with the second business is retained.
[0028] Among them, containers can divide the resources of a single operating system into different resource groups, so as to cope with more diverse resource usage requirements based on resource groups. Containers can isolate and restrict application processes through Linux namespace namespace and self-control group Cgroups technology. For example, the role of namespace is isolation, so that the application process can only see the data in the namespace, and the role of Cgroups is to limit the host resources allocated to the process, so as to realize the resource allocation and use of containers.
[0029] The first business can be any business that can trigger the creation of a container, which can be determined based on a common implementation method in the art, and the present disclosure does not limit this. After receiving a container creation request, the request can be responded to in the manner described in the present disclosure to create a corresponding target container. As described above, in a cold start scenario, if a container creation request is received, it is necessary to create a container from scratch. In this step, when the container is recycled, the container is not directly destroyed and released, but the component data in the container that is not related to the logic of the business is retained, so that container creation can be implemented in a reused form based on the recycled container.
[0030] As an example, component data in the container that is not associated with the logic of the business may include at least one of the following: Shim process, Cgroup, namespace, Network information, shared mount point, Capability (authority control) and Seccomp (security function). Among them, the Shim process is used to manage the life cycle of the container and has nothing to do with the business logic. Network includes elements such as ip (Internet Protocol, network layer protocol), mac (Media Access Control, media access control), veth pair, net ns, etc. Among them, veth pair is used to represent a pair of virtual device interfaces, and net ns (Network Namespace) is used to isolate network resources. In the FaaS scenario, the Capability / Seccomp configuration of the container is the same. Then at least part of the above content data in the container can be retained when the container is recycled.
[0031] In the art, starting a container at container runtime usually requires the following steps: Get the image file and create rootfs and a writable layer; create a shim process; create a namespace and set Cgroups; initialize the container init process; initialize the container network configuration, such as ip / mac / veth pair, etc.; mount the directory required by the container; initialize the container's security configuration, such as Capability and Seccomp, etc. In the present disclosure, container creation can be performed based on the recycled container, wherein the component data in the container that is not related to the logic of the business is retained, so that the same operation does not need to be repeated for such components during the container creation process, saving the time spent on container creation.
[0032] As an example, any container in the container pool may be used as the first container to respond to the container creation request.
[0033] In step 12, a root file system corresponding to the first service is obtained based on the image file of the first service.
[0034] In this step, the image file of the first service can be obtained and downloaded, and after downloading, the image file can be assembled and configured to obtain a root file system (rootfs) corresponding to the first service. The rootfs can be determined based on a common determination method in the art, and the present disclosure does not limit this.
[0035] In step 13, a target container required by the first service is created based on the first container and the root file system.
[0036] In this step, component data related to the service in the first container may be updated based on the root file system corresponding to the second service, so as to update the container based on the first container to obtain a target container required by the first service.
[0037] In the above technical solution, the created container is not directly destroyed when it is recycled, and the component data in the container that is not related to the logic of the business is retained. For example, namespace destruction usually consumes a lot of CPU resources, so the solution of the present disclosure can avoid the large consumption of resources caused by frequent creation and destruction of containers, and can avoid repeated allocation of resources to improve the efficiency of container creation. In addition, in the present disclosure, containers can be created based on containers in the container pool, so that the reuse of component data in the container that is not related to the logic of the business can be achieved, and the efficiency of container creation can be further improved, so that when the business traffic increases sharply, the creation of the container can be completed quickly and accurately, and the response to the burst traffic can be achieved, and the user access waiting time is reduced. In addition, the container pool maintains the recycled containers. Compared with the related art of pre-starting a certain number of instances with different resource specifications and language runtimes in the cluster to establish a container pool, the solution in the present disclosure can effectively reduce the occupation of the CPU, memory, and storage resources of the cluster, reduce the difficulty of maintaining the container pool, and improve the service stability when facing burst traffic loads.
[0038] In some embodiments, creating a target container required by the first service based on the first container and the root file system may include: The root file system of the first container is updated to the root file system corresponding to the first service, and the state information of the first container is updated to an ongoing state.
[0039] The image file bound to the first container may be replaced by replacing the root file system of the first container, thereby achieving container reuse.
[0040] As an example, updating the root file system of the first container to the root file system corresponding to the first service may include: Obtain a mount point of the root file system corresponding to the first service.
[0041] As an example, the root file system of the first container may be recorded as rootfs0, and the system corresponding to the first service may be recorded as rootfs1. For example, the mount point of the root file system rootfs1 corresponding to the first service may be obtained through the open_tree() system call.
[0042] Enter the mount namespace based on the handle of the mount namespace of the first container. The mount namespace is usually used to isolate the mount point of the file system. Each mount namespace has an independent file system mount point, so that the file systems in different mount namespaces are isolated. After the first container is created, the handle of its mount namespace can be determined, and then the mount namespace can be further entered based on the handle to perform corresponding operations in the mount namespace.
[0043] The mount point of the root file system corresponding to the first service is mounted to the subdirectory in the mount namespace. For example, rootfs1 can be moved to the subdirectory of rootfs0 through the move_mount() system call, thereby implementing the mounting of the root file system corresponding to the first service.
[0044] Afterwards, the root file system of the first container is switched to the subdirectory. For example, the rootfs1 and rootfs0 can be reversed through the pivot_root() system call. In this case, rootfs1 becomes the root file system of the mountnamespace of the first container, and rootfs0 becomes a sub-mount point of rootfs1. Furthermore, rootfs0 can be unmounted, thereby completing the replacement of the root file system of the first container.
[0045] Furthermore, the init process of the first container may be updated to the init process corresponding to the first service.
[0046] If the control system can trigger a signal after the switch of the root file system of the container is completed, the process in the first container can receive the signal and call exec() to execute the binary of the init process of the first business to switch the process of the first container to the init process of the first business. The functions called by the system in the above process are common functions in Linux and will not be described here.
[0047] Therefore, through the above technical solution, the root file system and init process of the container can be dynamically switched during the operation of the container, so as to realize the reuse of the recycled container, improve the efficiency of container creation, avoid the lock competition in the kernel during the container creation process to a certain extent, improve the efficiency of container supply, and ensure the stability of the service in response to sudden traffic. In addition, this solution can merge multiple resource sub-pools of the traditional reserved container instance solution, and dynamically switch the root file system of the container without distinguishing the language runtime, so as to enhance the elastic redundancy in response to sudden workloads under the condition of reserving equal resources, and can also reduce the total reserved resources of the platform by reducing the scale of reserved resources, saving costs.
[0048] In some embodiments, the method may further include: After creating the target container required by the first service, metadata of the target container is updated based on the state information of the target container and the root file system of the target container.
[0049] The metadata of the container may include information about the container, which may exist in the form of a label or annotation. For example, the metadata may include status information to identify the running status of the container. For example, when creating the target container, the target container is created based on the first container. Then, after the target container is created, its metadata information may be updated so that the metadata information corresponds to the target container. For example, the status information of the target container may be updated to in progress, and the root file system recorded in the metadata may be updated to the root file system of the target container.
[0050] Therefore, through the above technical solution, the corresponding metadata can be updated after the target container is created, so as to implement operations and queries on the target container based on the metadata, thereby facilitating unified management of the target container.
[0051] In some embodiments, the method may further include: In response to receiving a container release request for a second container, updating an init process of the second container to a dummy process.
[0052] The second container may be any container in the created containers. After the business process corresponding to the container is completed, the corresponding container may be released to complete resource recycling. The container release request may be triggered by a common method in the container field in this field. After receiving the release request of the second container, it indicates that the container is no longer used, and the resources of the container may be released at this time.
[0053] In this embodiment, in order to facilitate the reuse of containers and save resource consumption of container recycling, instead of directly destroying the second container, the init process of the second container can be updated to a dummy process. Among them, dummy can be used to represent a complete copy of a multi-process package. The dummy process occupies less resources and can respond to a signal to switch to the next process. Therefore, in this step, the recycled container can be put into operation by switching the process to avoid the container being destroyed during the recycling process.
[0054] The root file system of the second container is updated to the root file system corresponding to the dummy process, and the state of the second container is updated to a recycled state, wherein the binary corresponding to the dummy process is located.
[0055] The updated second container is stored in the container pool.
[0056] Among them, the implementation scheme of switching the root file system of the container has been described above and will not be repeated here. In this embodiment, the root file system of the second container can be used as rootfs0, and the root file system corresponding to the dummy process can be used as rootfs1 to complete the switching of the root file system based on the method described above. Among them, the root file system corresponding to the dummy process is a lightweight rootfs, so that less storage resources are consumed. In addition, by updating the state of the second container to a recycled state, the second container is identified as a recycled container so as to achieve reuse in the subsequent container creation process. As an example, after the second container is recycled, the metadata of the target container can be updated so that the metadata information corresponds to the current state of the second container, such as the state information of the second container can be updated to a recycled state, and the root file system recorded in the metadata can be updated to the root file system corresponding to the dummy process.
[0057] Therefore, through the above technical solution, when recycling containers, instead of directly destroying them, it is possible to effectively reduce the large amount of resource consumption caused by frequent creation and destruction of containers, such as the CPU resource consumption caused by the destruction of a large number of namespaces. It can also avoid repeated allocation of resources, thereby improving the overall efficiency of the system.
[0058] In some embodiments, the method may further include: Before storing the updated second container in the container pool, process resources occupied by the business process of the second container are released.
[0059] The business process of the second container may be used to represent a process related to the business to which the second container belongs, and the process resources may include CPU resources, handle resources, and memory resources, etc., thereby reducing the occupation of system resources by maintenance of containers in the container pool, reducing resource occupation, and realizing rapid creation of containers.
[0060] Delete component data in the second container that is logically associated with the business to which the second container belongs.
[0061] As an example, the logically associated component data of a business may include temporary storage layer data. For example, temporary files may be left after the execution of related functions in the business. If they are reused, data leakage may occur. In this case, the data in the temporary storage layer can be deleted to ensure the security of the business data and avoid affecting the data in the subsequently created containers.
[0062] In some embodiments, the container creation request includes container specification information, wherein the container specification information may be generated by the user through a configuration interface, such as 4U8G, which may indicate that the container requires 4 vCPUs and 8GB of memory. It may be configured and determined by the user based on a specific application scenario. If the user does not select a configuration, the default container specification information may be pre-set.
[0063] Accordingly, the step of creating a target container required by the first service based on the first container and the root file system includes: A target container required by the first service is created based on the container specification information, the first container, and the root file system.
[0064] In this step, the resources used by the container can be allocated through the container rule information, and based on the first container and the root file system, the root file system of the first container is updated to the root file system corresponding to the first business, and the status information of the first container is updated to the ongoing state; the init process of the first container is updated to the init process corresponding to the first business to replace the root file system of the first container, thereby creating a target container.
[0065] As an example, the data in the Cgroups of the container can be determined based on the container specification information, so as to implement restrictions on resources isolated in the namespace and weight settings based on Cgroups. For example, the total amount of resources used by the business can be limited to achieve the adaptation of the container to businesses of different specifications, and further improve the availability and adaptability of the recycled containers. In this solution, multiple resource sub-pools of the traditional reserved container instance solution can be merged. By dynamically determining the container specification information of the container, there is no need to distinguish the resource specifications required by the container, thereby enhancing the elastic redundancy for dealing with sudden workloads under the condition of reserving equal resources. The total amount of reserved resources on the platform can also be reduced by reducing the scale of reserved resources to save costs.
[0066] The following combination Figure 2 The disclosed scheme is exemplified.
[0067] Create a container based on the Y0 business requirements, where the container contains the init process of business Y0, and Figure 2The relevant configuration of part A in the figure is as follows, and the root file system of the container is the rootfs corresponding to the Y0 business, and the above information is recorded in the metadata. After that, the container is recycled, and the init process of the business Y0 in the container can be switched to the dummy process. The component data shown in A can be retained, and the root file system corresponding to the Y0 business in the container is switched to the rootfs corresponding to the dummy process, and the metadata is updated to record the latest information above. After that, if the Y1 business has the need to create a container, the dummy process in the container can be further switched to the init process of Y1. Similarly, the component data shown in part A can be reused, and the rootfs corresponding to the dummy process in the container is switched to the rootfs of the Y1 business, and the metadata is updated to record the latest information above. Thus, a created container can realize container recycling and container reuse in the above manner, so as to adapt to multiple different business scenarios, improve the efficiency of container creation through container reuse, reduce container creation delay and improve container supply efficiency, and also simplify the resource occupation of the maintenance of containers in the container pool.
[0068] Based on the same inventive concept, the present disclosure also provides a container creation device, such as Figure 3 As shown, the device 10 comprises: The acquisition module 100 is configured to acquire a first container from a container pool in response to receiving a container creation request of a first service, wherein the container pool includes a container obtained by recycling a container created by a second service, and component data in the container that is not logically associated with the second service is retained; A determination module 200, configured to obtain a root file system corresponding to the first service based on the image file of the first service; The creation module 300 is used to create a target container required by the first service based on the first container and the root file system.
[0069] Optionally, the creation module includes: A first updating submodule, configured to update the root file system of the first container to the root file system corresponding to the first service, and update the state information of the first container to an ongoing state; The second updating submodule is used to update the init process of the first container to the init process corresponding to the first service.
[0070] Optionally, the first updating submodule includes: A first acquisition submodule, used to acquire a mount point of a root file system corresponding to the first service; A first processing submodule, configured to enter the mount namespace based on a handle of the mount namespace of the first container; A second processing submodule, used for mounting the mount point of the root file system corresponding to the first service to the subdirectory in the mount namespace; The switching submodule is used to switch the root file system of the first container to the subdirectory.
[0071] Optionally, the device further comprises: The first updating module is used to update metadata of the target container based on the state information of the target container and the root file system of the target container after creating the target container required by the first service.
[0072] Optionally, the device further comprises: A second updating module, configured to update the init process of the second container to a dummy process in response to receiving a container release request for the second container; A third updating module, configured to update the root file system of the second container to the root file system corresponding to the dummy process, and update the state of the second container to a recycled state; A storage module is used to store the updated second container in the container pool.
[0073] Optionally, the device further comprises: a processing module, configured to release process resources occupied by the business process of the second container before storing the updated second container in the container pool; The deleting module is used to delete the component data in the second container that is logically associated with the business to which the second container belongs.
[0074] Optionally, the container creation request includes container specification information; The creation module is further used to: A target container required by the first service is created based on the container specification information, the first container, and the root file system.
[0075] Reference below Figure 4 , which shows an electronic device (eg, Figure 1 The terminal device in the embodiment of the present disclosure may include but is not limited to mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 4 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0076] like Figure 4 As shown, the electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0077] Typically, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 4 The electronic device 600 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead.
[0078] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed.
[0079] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. Computer readable signal media may also be any computer readable medium other than computer readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0080] In some embodiments, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0081] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0082] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: in response to receiving a container creation request of a first business, obtains a first container from a container pool, wherein the container pool includes a container obtained by recycling a container created by a second business, and component data in the container that is not logically associated with the second business is retained; based on the image file of the first business, obtains a root file system corresponding to the first business; and based on the first container and the root file system, creates a target container required by the first business.
[0083] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or a combination thereof, including, but not limited to, object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0084] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0085] The modules involved in the embodiments described in the present disclosure may be implemented by software or hardware. The name of the module does not limit the module itself in some cases. For example, the acquisition module may also be described as "a module for acquiring a first container from a container pool in response to receiving a container creation request of a first service".
[0086] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0087] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0088] According to one or more embodiments of the present disclosure, Example 1 provides a container creation method, wherein the method includes: In response to receiving a container creation request of the first service, obtaining a first container from a container pool, wherein the container pool includes a container obtained by recycling a container created by the second service, and component data in the container that is not logically associated with the second service is retained; Based on the image file of the first business, obtaining a root file system corresponding to the first business; A target container required by the first service is created based on the first container and the root file system.
[0089] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, wherein creating a target container required by the first service based on the first container and the root file system includes: Updating the root file system of the first container to the root file system corresponding to the first service, and updating the status information of the first container to an ongoing status; The init process of the first container is updated to the init process corresponding to the first service.
[0090] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2, wherein updating the root file system of the first container to the root file system corresponding to the first service includes: Obtaining a mount point of a root file system corresponding to the first service; Entering the mount namespace based on the handle of the mount namespace of the first container; Mounting the mount point of the root file system corresponding to the first service to the subdirectory in the mount namespace; Switch the root file system of the first container to the subdirectory.
[0091] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2, wherein the method further includes: After creating the target container required by the first service, metadata of the target container is updated based on the state information of the target container and the root file system of the target container.
[0092] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 1, wherein the method further includes: In response to receiving a container release request for a second container, updating an init process of the second container to a dummy process; Updating the root file system of the second container to the root file system corresponding to the dummy process, and updating the state of the second container to a recycled state; The updated second container is stored in the container pool.
[0093] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 5, wherein the method further includes: Before storing the updated second container in the container pool, releasing process resources occupied by the business process of the second container; Component data in the second container that is logically associated with the service to which the second container belongs is deleted.
[0094] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 1, wherein the container creation request includes container specification information; The creating a target container required by the first service based on the first container and the root file system includes: A target container required by the first service is created based on the container specification information, the first container, and the root file system.
[0095] According to one or more embodiments of the present disclosure, Example 8 provides a container creation device, the device comprising: an acquisition module, configured to acquire a first container from a container pool in response to receiving a container creation request of a first service, wherein the container pool includes a container obtained by recycling a container created by a second service, and component data in the container that is not logically associated with the second service is retained; A determination module, configured to obtain a root file system corresponding to the first service based on the image file of the first service; A creation module is used to create a target container required by the first service based on the first container and the root file system.
[0096] According to one or more embodiments of the present disclosure, Example 9 provides a computer-readable medium having a computer program stored thereon, which implements the steps of any of the methods described in Examples 1-7 when executed by a processing device.
[0097] According to one or more embodiments of the present disclosure, Example 10 provides an electronic device, including: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of any one of the methods described in Examples 1-7.
[0098] According to one or more embodiments of the present disclosure, Example 11 provides a computer program product, including a computer program, which implements the steps of any one of the methods of Examples 1-7 when executed by a processor.
[0099] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present disclosure (but not limited to) by each other to form a technical solution.
[0100] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0101] Although the subject matter has been described in language specific to structural features and / or method logic actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims. Regarding the device in the above embodiment, the specific manner in which each module performs the operation has been described in detail in the embodiment related to the method, and will not be elaborated here.
Claims
1. A container creation method, characterized in that: The method comprises: In response to receiving a container creation request of the first service, obtaining a first container from a container pool, wherein the container pool includes a container obtained by recycling a container created by the second service, and component data in the container that is not logically associated with the second service is retained; Based on the image file of the first business, obtaining a root file system corresponding to the first business; A target container required by the first service is created based on the first container and the root file system.
2. The method according to claim 1, characterized in that: The creating a target container required by the first service based on the first container and the root file system includes: Updating the root file system of the first container to the root file system corresponding to the first service, and updating the status information of the first container to an ongoing status; The init process of the first container is updated to the init process corresponding to the first service.
3. The method according to claim 2, characterized in that The updating the root file system of the first container to the root file system corresponding to the first service includes: Obtaining a mount point of a root file system corresponding to the first service; Entering the mount namespace based on the handle of the mount namespace of the first container; Mounting the mount point of the root file system corresponding to the first service to the subdirectory in the mount namespace; Switch the root file system of the first container to the subdirectory.
4. The method according to claim 2, characterized in that: The method further comprises: After creating the target container required by the first service, metadata of the target container is updated based on the state information of the target container and the root file system of the target container.
5. The method according to claim 1, characterized in that The method further comprises: In response to receiving a container release request for a second container, updating an init process of the second container to a dummy process; Updating the root file system of the second container to the root file system corresponding to the dummy process, and updating the state of the second container to a recycled state; The updated second container is stored in the container pool.
6. The method according to claim 5, characterized in that The method further comprises: Before storing the updated second container in the container pool, releasing process resources occupied by the business process of the second container; Delete component data in the second container that is logically associated with the service to which the second container belongs.
7. The method according to claim 1, characterized in that The container creation request includes container specification information; The creating a target container required by the first service based on the first container and the root file system includes: A target container required by the first service is created based on the container specification information, the first container, and the root file system.
8. A container creation device, characterized in that: The device comprises: an acquisition module, configured to acquire a first container from a container pool in response to receiving a container creation request of a first service, wherein the container pool includes a container obtained by recycling a container created by a second service, and component data in the container that is not logically associated with the second service is retained; A determination module, configured to obtain a root file system corresponding to the first service based on the image file of the first service; A creation module is used to create a target container required by the first service based on the first container and the root file system.
9. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 7 are implemented.
10. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Sandbox management method, electronic equipment and computer readable storage medium
CN122490506A