Method for online hot modification of containerized nacos key

By deploying the Nacos service cluster on the container orchestration platform, the timeliness of Nacos keys and tokens are modified without shutdown, solving the problem of downtime in key management and improving the availability and security of the system.

CN120128335APending Publication Date: 2025-06-10QIMING INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510360625.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In containerized deployment environments, key management of middleware such as Nacos has problems with downtime maintenance, affecting service continuity and business availability.

Method used

By deploying a Nacos service cluster on the container orchestration platform, using the Nacos configuration file to define the token timeliness setting value, and modifying the Nacos key and token timeliness without shutting down, ensuring high availability of services with the help of the container orchestration platform's rolling restart and health check mechanism.

Benefits of technology

It realizes online hot update of Nacos keys, avoids service downtime caused by key updates, improves system availability and security, can respond to security threats in a timely manner, and reduces the risk of being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128335A_ABST
    Figure CN120128335A_ABST
Patent Text Reader

Abstract

The invention discloses a method for online hot modification of a containerized nacos key, and the method comprises the steps: S1, deploying a Nacos service cluster on a container arrangement platform; s2, defining a timeliness set value of the Nacos token through the Nacos configuration file; s3, the Nacos secret key is modified; and S4, after the secret key is modified, the timeliness of the token is modified to the original value again, and the Nacos service pressure is relieved. According to the scheme, the online hot modification of the key of the Nacos is realized in the containerized environment, so that the problem of service interruption in the key modification process is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, and in particular to a method for online hot modification of containerized nacos keys. Background Art

[0002] With the wide adoption of cloud computing and microservices architecture, containerization technology has become an important part of enterprise IT architecture due to its lightweight, easy deployment, and high efficiency characteristics. As a service discovery and configuration management middleware, Nacos plays an important role in the microservices architecture. It supports dynamic service discovery, dynamic configuration management, and service health check, greatly improving the flexibility and maintainability of the microservices architecture.

[0003] However, in the containerized deployment environment, the security management of middleware such as Nacos has become a challenge. Especially key management, which is the key to ensuring the security of middleware. Traditional key update methods usually require downtime maintenance, which not only affects the continuity of services but also impacts the business. Therefore, how to achieve real-time update of middleware keys without downtime has become a technical problem to be solved urgently. Summary of the Invention

[0004] In view of the above technical problems, the present invention provides a method for online hot modification of containerized nacos keys.

[0005] The present invention is implemented by the following technical solutions: A method for online hot modification of containerized nacos keys, comprising the following steps: Step S1: Deploy a Nacos service cluster on a container orchestration platform; Step S2: Define the Nacos token timeliness setting value through the Nacos configuration file; Step S3: Modify the Nacos key; Step S4: After the key modification is completed, modify the token timeliness back to the original value to relieve the Nacos service pressure.

[0006] Specifically, in step S1, the Nacos service cluster is a three-node cluster, and the Nacos configuration file is mounted to each Pod of the Nacos cluster in the form of a configuration dictionary to achieve configuration persistence and unification.

[0007] Specifically, the setting of the Nacos token timeliness in step S2 is as follows: The default default value is 5 hours, the token validity period is 5 hours. When it exceeds 5 hours, the application side needs to re-apply to the server to generate a new token and cache it locally; After the key update is completed, restore this value to the original value as appropriate.

[0008] Specifically, the modification of the Nacos key in step S3 includes: Modify the timeliness definition value from 5 hours to 5 seconds; After the token timeliness is modified to 5 seconds, wait for more than 5 hours to ensure that all tokens cached locally by the clients have expired, and cache the tokens with a timeliness of 5 seconds that have been generated to the local; Formally modify the key value, and the length of the new key value is not less than 32 bits.

[0009] Specifically, step S4 further includes: by means of the rolling restart, health check, and readiness probe of the container orchestration platform, restart the Pods of the Nacos cluster in sequence to ensure that at least one Pod node provides services externally normally at the same time.

[0010] The beneficial effects of the present invention are as follows: The present invention effectively solves the problem of service interruption during the key modification process by realizing the online hot modification of the Nacos key in a containerized environment; the Nacos key can be modified in real time without a downtime window. By realizing the online hot update of the key, the service downtime caused by key update is avoided, and the availability of the system is improved. The dynamic update of the key can respond to security threats in a timely manner, strengthen the security of the middleware, and reduce the risk of being attacked. It solves the problem that key update requires downtime: The traditional key update method requires downtime for implementation. The present invention realizes the online dynamic update of the key through a hot update mechanism without downtime, ensuring that the business operation is not affected in any way during the key update process and achieving a truly seamless switch. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the structures shown in these drawings without creative efforts.

[0012] Figure 1 It is a flowchart of the method for online hot modification of the containerized nacos key in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0013] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0014] It should be noted that similar reference numerals and letters denote similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0015] The following will Figure 1 be combined with the attached

[0016] The present invention proposes a method for online hot modification of containerized nacos keys, including the following steps: Step S1: Deploy a Nacos service cluster on a container orchestration platform; Step S2: Define the Nacos token timeliness setting value through the Nacos configuration file; Step S3: Modify the Nacos key; Step S4: After the key modification is completed, modify the token timeliness back to the original value to relieve the pressure on the Nacos service.

[0017] In this embodiment, the Nacos service cluster in Step S1 is a three-node cluster, and the Nacos configuration file is mounted to each Pod of the Nacos cluster in the form of a configuration dictionary to achieve configuration persistence and unification.

[0018] The setting of the Nacos token timeliness in Step S2 is specifically as follows: The default default value is 5 hours, the token validity period is 5 hours. When it exceeds 5 hours, the application side needs to re-apply to the server to generate a new token and cache it locally; After the key is updated, restore this value to the original value as appropriate.

[0019] Modifying the Nacos key in Step S3 includes: Modify the timeliness definition value from 5 hours to 5 seconds; After the token timeliness is modified to 5 seconds, wait for more than 5 hours to ensure that all tokens cached locally by the clients have expired, and cache the tokens with a timeliness of 5 seconds that have been generated and cached locally; Formally modify the key value, and the length of the new key value is not less than 32 bits.

[0020] Step S4 further includes: By means of the rolling restart, health check and readiness probe of the container orchestration platform, restart the Pods of the Nacos cluster in sequence to ensure that at least one Pod node can normally provide services externally at the same time.

[0021] In one embodiment, to achieve online hot modification of Nacos keys, the following technologies are required: Containerization technology (Docker / Kubernetes): Containerization technology realizes the consistent deployment and rapid expansion of applications by packaging the application and its dependencies in a container image. As a container platform, Docker provides mechanisms for packaging, distributing, and running containers. Kubernetes, on the other hand, is a container orchestration tool that supports the automatic deployment, expansion, and management of containerized applications and is a key technology for achieving high availability, scalability, and flexibility.

[0022] Configuration dictionary (ConfigMap): ConfigMap, as a key resource object for storing configuration information in the Kubernetes environment, is also extremely important for the containerized deployment and configuration management of Nacos itself. In the scenario of blue-green deployment of containerized Nacos, ConfigMap is used to store the configuration information of Nacos itself, such as necessary service configurations like database connection information. In this way, the Nacos service can directly read the configuration from ConfigMap when starting and running, without hard-coding the configuration in the image or traditional configuration files.

[0023] Token timeliness setting: Token timeliness setting is an important mechanism for improving system security. By setting an expiration time for the token to limit its usage time window, it reduces security risks caused by token leakage. This mechanism forces the client to update the token regularly, increasing the frequency of system security checks and also meeting the requirements of security specifications and compliance standards.

[0024] In this embodiment, the present invention provides a method for online hot modification of containerized Nacos keys, which can dynamically update the keys of the containerized deployed Nacos service without downtime. The specific solution is as follows: 1. Containerize and deploy the Nacos service cluster: Deploy the Nacos service cluster on a container orchestration platform (such as Kubernetes). This cluster is a three-node cluster. Among them, the Nacos configuration file is mounted into each Pod of the Nacos cluster in the form of a configuration dictionary (Configmap) to achieve configuration persistence and unification.

[0025] 2. Nacos token timeliness setting: The Nacos token timeliness setting value is defined through the Nacos configuration file. The default value is 5 hours, that is, the token is valid for 5 hours. After 5 hours, the application side needs to re-apply to the server to generate a new token and cache it locally. When modifying the key, the timeliness definition value needs to be modified from 5 hours to 5 seconds. After the key update is completed, restore the value to the original value as appropriate.

[0026] 3. Modify the Nacos key: After the token validity is changed to 5 seconds, you need to wait for more than 5 hours. The purpose is to ensure that all tokens cached locally on the client have expired, and a token with a validity of 5 seconds has been generated and cached locally. Then formally modify the key value. It is recommended that the new key value length is not less than 32 bits.

[0027] 4. Nacos new key takes effect: After the key modification is completed, modify the token validity to the original value to reduce the pressure on the Nacos service. Restart the Nacos service cluster to make the new key effective. With the help of Kubernetes' rolling restart, health check, and readiness probe, the Pods of the Nacos cluster will restart in sequence, and ensure that at least one Pod node can provide services normally at the same time, truly realizing that the client is not aware of the key modification.

[0028] This solution combines containerized architecture design with dynamic configuration management technology to build a complete key hot update system. The specific implementation is divided into the following core modules: (1) Dynamic configuration management system: Adopt the dual-channel mechanism of Kubernetes Configmap + Nacos configuration center. The basic configuration is solidified in Configmap and mounted to the Nacos container through volumeMounts. (2) Dynamic adjustment of token validity: Time-dependent gradient adjustment strategy: Warm-up phase: 5h → 1h → 10m → 30s, decreasing in stages Update phase: Maintain a stable 5s window Recovery phase: 30s → 10m → 1h, increasing in stages (3) Zero downtime rolling restart: Through the Nacos blue-green deployment scheduling method, the service request traffic is forwarded to the Nacos cluster with the newly effective key, thus achieving zero downtime.

[0029] The main advantages of this technical solution include: Flexibility: Nacos keys can be modified in real time without downtime windows.

[0030] High availability: By implementing online hot update of keys, service downtime caused by key update is avoided, thus improving system availability.

[0031] Security enhancement: Dynamic key updates can respond to security threats in a timely manner, strengthen middleware security, and reduce the risk of attacks.

[0032] Solve the problem that key update requires system downtime: Traditional key update methods need to shut down the system for operation. The present invention realizes online dynamic key update through a hot update mechanism without system downtime.

[0033] Zero business awareness: Ensure that during the key update process, business operations are not affected at all, achieving a truly seamless switch.

[0034] For the foregoing embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily required by this application.

[0035] In the above embodiments, the basic principles, main features and advantages of the present invention are described. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, any modifications and changes made by those skilled in the art that do not depart from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.

Claims

1. A method for online hot modification of containerized nacos keys, characterized in that: The following steps are involved: Step S1: Deploy the Nacos service cluster on the container orchestration platform; Step S2: Define the Nacos token validity setting value through the Nacos configuration file; Step S3: Modify the Nacos key; Step S4: After the key modification is completed, modify the token validity to the original value to reduce the pressure on Nacos service.

2. A method for online hot modification of containerized nacos keys as claimed in claim 1, characterized in that: In step S1, the Nacos service cluster is a three-node cluster, and the Nacos configuration file is mounted to each Pod of the Nacos cluster in the form of a configuration dictionary to achieve configuration persistence and unification.

3. A method for online hot modification of containerized nacos keys as claimed in claim 1, characterized in that: The setting of the validity of the Nacos token in step S2 is specifically as follows: The default value is 5 hours. The token is valid for 5 hours. When it exceeds 5 hours, the application needs to apply to the server to generate a new token and cache it locally. After the key is updated, the value is restored to the original value as appropriate.

4. A method for online hot modification of containerized nacos keys as claimed in claim 1, characterized in that: The step S3 of modifying the Nacos key includes: Modify the timeliness definition value from 5 hours to 5 seconds; After the token validity period is changed to 5 seconds, wait for more than 5 hours to ensure that all tokens cached locally on the client have expired, and then save the generated and cached token with a validity period of 5 seconds to the local client. The key value is officially modified, and the length of the new key value is not less than 32 bits.

5. A method for online hot modification of containerized nacos keys as claimed in claim 1, characterized in that: The step S4 also includes: restarting the Pods of the Nacos cluster in sequence with the help of the rolling restart, health check and readiness probe of the container orchestration platform to ensure that at least one Pod node provides normal services to the outside world at the same time.