Application starting method, device and system based on Kubernetes

By deploying related services in Kubernetes clusters, synergistically read and combine dynamic and static configuration information of privacy computing applications, the problem of inefficient startup of privacy computing applications is solved, and rapid and secure application startup is achieved.

CN120144207AActive Publication Date: 2025-06-13ZHEJIANG ANT MISUAN TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510221264.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-13
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

When starting a privacy computing application, it needs to rely on dynamic configuration information and static configuration information, resulting in the impact of startup efficiency.

Method used

By deploying task orchestration services, load management services, configuration rendering plug-ins, and configuration management services in a Kubernetes cluster, these services work together to read and combine dynamic and static configuration information, generate final configuration information and launch a privacy computing application.

Benefits of technology

This enables simple and fast startup of privacy computing applications, improves startup efficiency, and ensures the security of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144207A_ABST
    Figure CN120144207A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an application starting method based on Kubernetes, and relates to a first party and a second party, a task arrangement service is deployed in the first party, and a load management service, a configuration rendering plug-in and a configuration management service are deployed in the second party. The method comprises the steps that a task arrangement service creates a first resource in a Kubernetes cluster to which the task arrangement service belongs and in a namespace of a second party according to a starting instruction of a privacy computing application, and the first resource is used for storing input parameters and a starting configuration template of the privacy computing application; and the load management service monitors that the first resource is created in the namespace of the second party, and sends a calling instruction to the configuration rendering plug-in. And the configuration rendering plug-in reads target information registered for the privacy computing application in advance from the configuration management service, and correspondingly fills the input parameters and the target information into the startup configuration template to obtain configuration information of the privacy computing application. The load management service launches the privacy computing application based on the configuration information received from the configuration rendering plug-in.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of computer technology, and in particular, to an application startup method, device, and system based on Kubernetes. Background Art

[0002] Currently, the emergence of Kubernetes has promoted the popularization and implementation of popular technologies such as microservice architectures, making development, operation, and delivery increasingly simple. Therefore, more and more enterprises use Kubernetes as an internal container orchestration platform to improve enterprise production efficiency.

[0003] In the privacy computing scenario, the startup of privacy computing applications usually requires different types of configuration information such as dynamic configuration information and static configuration information. For different types of configuration information, privacy computing applications need to read them in different ways, which will affect the startup efficiency of privacy computing applications. Summary of the Invention

[0004] One or more embodiments of this specification describe an application startup method, device, and system based on Kubernetes, which can start privacy computing applications simply and quickly.

[0005] In a first aspect, there is provided an application startup method based on Kubernetes, involving a first party and a second party. A task orchestration service is deployed in the first party, and a load management service, a configuration rendering plugin, and a configuration management service are deployed in the second party; the method includes:

[0006] According to the startup instruction of the privacy computing application, the task orchestration service creates a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs. This first resource is used to store the input parameters and startup configuration template of the privacy computing application;

[0007] When the load management service monitors the creation of the first resource in the namespace of the second party, it sends a call instruction to the configuration rendering plugin;

[0008] The configuration rendering plugin reads the target information pre-registered for the privacy computing application from the configuration management service, and fills the input parameters and the target information into the startup configuration template correspondingly to obtain the configuration information of the privacy computing application;

[0009] The load management service starts the privacy computing application based on the configuration information received from the configuration rendering plugin.

[0010] Second aspect, a Kubernetes-based application startup method is provided, which involves a first party and a second party. A load management service, a configuration rendering plugin, and a configuration management service are deployed in the second party. The method includes:

[0011] When the load management service monitors that the first party creates a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs, it sends a call instruction to the configuration rendering plugin. The first resource is used to store the input parameters and startup configuration template of the privacy computing application.

[0012] The call instruction is used to instruct the configuration rendering plugin to read the target information pre-registered for the privacy computing application from the configuration management service, and correspondingly fill the input parameters and the target information into the startup configuration template to obtain the configuration information of the privacy computing application.

[0013] The load management service starts the privacy computing application based on the configuration information received from the configuration rendering plugin.

[0014] Third aspect, a Kubernetes-based application startup system is provided, including a first party and a second party.

[0015] The first party is used to create a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs according to the startup instruction of the privacy computing application. This first resource is used to store the input parameters and startup configuration template of the privacy computing application.

[0016] The second party is used to monitor the creation of the first resource in its own namespace, read the target information pre-registered for the privacy computing application from local, and correspondingly fill the input parameters and the target information into the startup configuration template to obtain the configuration information of the privacy computing application.

[0017] The second party is used to start the privacy computing application based on the configuration information.

[0018] Fourth aspect, a Kubernetes-based application startup device is provided, which is set in the second party. The device includes:

[0019] A reading unit, which is used to monitor that the first party creates a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs, and read the target information pre-registered for the privacy computing application. The first resource is used to store the input parameters and startup configuration template of the privacy computing application.

[0020] A generation unit, configured to fill the input parameters and target information into the startup configuration template correspondingly to obtain the configuration information of the privacy computing application;

[0021] A startup unit, configured to start the privacy computing application based on the configuration information.

[0022] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method of the first or second aspect.

[0023] In a sixth aspect, a computing device is provided, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method of the first or second aspect is implemented.

[0024] The method for starting an application based on Kubernetes provided by one or more embodiments of this specification. The dynamically changing configuration information (referred to as dynamic configuration information for short) on which the startup of the privacy computing application depends is provided by the first party that initiates the privacy computing application startup instruction to the second party that needs to start the privacy computing application, while the fixed and unchanging configuration information (referred to as static configuration information for short) of the privacy computing application is locally maintained by the second party. Specifically, when starting the privacy computing application at the second party, the final configuration information of the privacy computing application is determined by combining the dynamic configuration information received from the first party and the static configuration information locally maintained, and the privacy computing application is started based on it. In this way, the privacy computing application can be started simply and quickly. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] To more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0026] Figure 1 It is a schematic diagram of an implementation scenario of an embodiment disclosed in this specification;

[0027] Figure 2 It shows a schematic diagram of the method for starting an application based on Kubernetes according to an embodiment of this specification;

[0028] Figure 3 It shows a schematic diagram of the system for starting an application based on Kubernetes according to an embodiment of this specification;

[0029] Figure 4Schematic diagram of a Kubernetes-based application startup device according to an embodiment of this specification. Detailed implementation manners

[0030] The solution provided in this specification will be described below with reference to the accompanying drawings.

[0031] As described above, the startup of a privacy computing application usually requires different types of configuration information such as static configuration information and dynamic configuration information. To quickly and effectively start the privacy computing application, the inventors of this solution propose that for the dynamic configuration information on which the startup of the privacy computing application depends, it is provided by the first party that initiates the privacy computing application startup instruction to the second party that needs to start the privacy computing application, while the fixed and unchanging configuration information (referred to as static configuration information) of the privacy computing application is locally maintained by the second party. In this way, when starting the privacy computing application at the second party, the final configuration information of the privacy computing application is determined by combining the dynamic configuration information received from the first party and the static configuration information locally maintained, and the privacy computing application is started based on it, so that the privacy computing application can be started simply and quickly.

[0032] It should be noted that for the sensitive information on which the startup of the privacy computing application depends, it can be maintained locally by the second party as part of the above-mentioned static configuration information. In this way, the security of the sensitive information can be ensured, that is to say, this solution can ensure that the privacy computing application can be started simply and quickly under the condition of privacy data security.

[0033] The above is the inventive concept provided in this specification. Based on this inventive concept, this solution can be implemented. The following will describe this solution in detail.

[0034] Figure 1 Schematic diagram of the implementation scenario of an embodiment disclosed in this specification Figure 1 In it, before starting the privacy computing application, the administrator of the second party can register the target information (also called static configuration information) on which the startup of the privacy computing application depends in the configuration management service. Among them, in the case where the target information includes sensitive information, the sensitive information can be entrusted to a key escrow service (an information security service).

[0035] Then, the task submitter (for example, a user) can call the create task interface of the task orchestration service to initiate a privacy computing application startup instruction, and the startup instruction can include the input parameters of the privacy computing application. After that, the task orchestration service can create an application configuration management (ConfigMap) resource and / or Pod resource (hereinafter also referred to as Pod) for storing the input parameters of the privacy computing application and the startup configuration template in the namespace of the second party in the Kubernetes cluster to which it belongs.

[0036] The load management service in the second party monitors the creation of ConfigMap resources and / or Pod resources under the namespace of the second party, and sends a call instruction to the configuration rendering plugin. The configuration rendering plugin reads the target information pre-registered for the privacy computing application from the configuration management service, and fills the input parameters and the target information into the startup configuration template as dynamic configuration information and static configuration information respectively, to obtain the final configuration information of the privacy computing application. The load management service starts the application container corresponding to the privacy computing application based on the final configuration information received from the configuration rendering plugin.

[0037] It should be noted that in the scenario where multiple institutions jointly execute privacy computing tasks, the above-mentioned first party can be deployed in any institution, and the second party can be deployed in each institution. In the following description of this specification, the institution where the first party is deployed can be referred to as the initiating party, and the other institutions where the second party is deployed can be referred to as participating parties.

[0038] Figure 2 The figure shows a schematic diagram of an application startup method based on Kubernetes according to an embodiment of this specification. This method involves a first party and a second party. The task orchestration service is deployed in the first party, and the load management service, the configuration rendering plugin, and the configuration management service are deployed in the second party.

[0039] As Figure 2 shown, the method may include the following steps:

[0040] Step S202, the task orchestration service receives the startup instruction of the privacy computing application.

[0041] The above-mentioned privacy computing application can be used to perform privacy computing such as private intersection, random splitting, model training, and prediction.

[0042] In addition, the above-mentioned startup instruction can specifically be initiated by a task submitter (such as a user) by calling the create task interface of the task orchestration service, which indicates the input parameters of the privacy computing application.

[0043] Exemplarily, the above-mentioned input parameters may include dynamically changing information such as task identifiers and data sources. These dynamically changing information are the configuration information on which the startup of the privacy computing application depends, so the input parameters can also be referred to as the dynamic configuration information of the privacy computing application.

[0044] In practice, the above-mentioned startup instruction may also indicate the description information of the second party. The description information may include the namespace identifier of the second party and the resource configuration information, etc.

[0045] Step S204: According to the start instruction, the task scheduling service creates a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs. This first resource is used to store the input parameters and start configuration template of the privacy computing application.

[0046] In one embodiment, the above start configuration template includes field A corresponding to dynamic configuration information and field B corresponding to static configuration information (described later). It should be understood that since the dynamic configuration information is the input parameter of the privacy computing application, field A can also be understood as the field corresponding to the input parameter of the privacy computing application.

[0047] In practice, the number of the above field A and field B can both be multiple.

[0048] In addition, the above start configuration template may further include placeholder X corresponding to the field value of field A and placeholder Y corresponding to the field value of field B. More specifically, placeholder X indicates the field name of field A, and placeholder Y indicates the field name of field B.

[0049] Specifically, the namespace of the second party can be located according to the namespace identifier in the description information of the second party, and in this namespace, the above first resource is created according to the resource configuration information in the description information of the second party.

[0050] In one embodiment, the number of the above first resources is two, and the two first resources are respectively used to store the input parameters and start configuration template of the privacy computing application.

[0051] Among them, the above two first resources can both be ConfigMap resources or Pod resources, or one can be a ConfigMap resource and the other can be a Pod resource.

[0052] Taking the above two first resources both being ConfigMap resources as an example, the content of the ConfigMap resource used to store the input parameters of the privacy computing application can be seen in the following code segment:

[0053]

[0054]

[0055] Among them, in the above code segment, the field values of the two fields "TASK_CONF I G" and "TASK_ID" in lines 3-4 are the input parameters or dynamic configuration information of the privacy computing application.

[0056] In addition, the content of the ConfigMap resource used to store the start configuration template of the privacy computing application can be seen in the following code segment:

[0057]

[0058] Among them, in the above code segment, lines 5-8 are the startup configuration template for the privacy computing application, which includes fields corresponding to dynamic configuration information: "task_id" and "task_config", and fields corresponding to static configuration information: "user_name" and "db_password". In addition, "{.TASK_ID}" and "{.TASK_CONFIG}" are placeholders corresponding to the field values of the fields "task_id" and "task_config" respectively, and "{.TASK_USERNAME}" and "{.TASK_DB_PASSWORD}" are placeholders corresponding to the field values of the fields "user_name" and "db_password" respectively.

[0059] Taking the above two first resources both being Pod resources as an example, the input parameters and startup configuration template of the privacy computing application can be included in the fields "Env" or "Annotation" of the Pod resource.

[0060] It should be noted that in the case where the above two first resources are both ConfigMap resources, the task orchestration service can also create Pod resources, Service resources, etc. in the namespace of the second party.

[0061] Step S206, the load management service monitors the creation of the first resource in the namespace of the second party and sends a call instruction to the configuration rendering plugin.

[0062] As mentioned above, the first resource here can be a ConfigMap resource or a Pod resource.

[0063] In the embodiments of this specification, the load management service can apply in advance to the control plane (APIServer) of the Kubernetes cluster to monitor changes (including resource creation, modification, and deletion) of resources such as ConfigMap, Pod, and service discovery (Service).

[0064] In a specific embodiment, the monitoring of changes to resources such as ConfigMap, Pod, and Service can be implemented based on the list-watch mechanism of Kubernetes.

[0065] Taking the monitoring of the creation of ConfigMap resources as an example, when a ConfigMap resource is created in the namespace of the second party in the Kubernetes cluster, the control plane sends an event change notification to the load management service, and the event change notification includes the created ConfigMap resource.

[0066] It should be understood that since the first resource contains the startup configuration template and input parameters of the privacy computing application, when the load management service monitors the above first resource, it can obtain the startup configuration template and input parameters. Then, the load management service can send a call instruction to the configuration rendering plugin, and the call instruction can include the startup configuration template and input parameters.

[0067] In addition, in the case where the task orchestration service also creates a Pod resource in the namespace of the second party, the load management service creates a Pod in the second party for subsequently pulling up the application container corresponding to the privacy computing application therein.

[0068] Step S208, the configuration rendering plugin reads the target information pre-registered for the privacy computing application from the configuration management service, and fills the input parameters and the target information into the startup configuration template correspondingly to obtain the configuration information of the privacy computing application.

[0069] In this solution, before starting the privacy computing application, the administrator of the second party can pre-register the target information on which the startup of the privacy computing application depends with the configuration management service.

[0070] The target information can include two parts: the first part is sensitive information such as the accounts and passwords for the privacy computing application to log in to the database and file storage service; the second part is non-sensitive information such as the log level and output parameter types of the privacy computing application. The log level can be, for example: ERROR, WARNING, INFO, DEBUG, TRACE, etc. The output parameter types can be, for example, model parameters, etc. Usually, the target information is fixed and unchanged, so it can also be called the static configuration information of the privacy computing application.

[0071] For the above sensitive information, in order to ensure its security, the configuration management service further manages it through the key escrow service.

[0072] The specific process for the above configuration rendering plugin to read the target information can include: the configuration rendering plugin can parse the startup configuration template to obtain the field name of field B corresponding to the target information (i.e., static configuration information), and then, according to the field name of field B, read the target information from the configuration management service.

[0073] Among them, in the above startup configuration template, there is also a placeholder Y corresponding to the field value of field B (i.e., the field corresponding to the static configuration information), and when this placeholder Y indicates the field name of field B, the field name of field B can be determined according to this placeholder Y.

[0074] In addition, as mentioned above, the target information may include sensitive information. In the case where the sensitive information is also included, after receiving the target field name corresponding to the sensitive information, the configuration management service may read the sensitive information from the key escrow service according to the target field name.

[0075] Taking the code segment corresponding to the above startup configuration template as an example, the target field names corresponding to the sensitive information obtained by parsing may include: "USE_RNAME" and "DB_PASSWORD". Then, the configuration management service may read the corresponding field values as sensitive information from the key escrow service according to "USE_RNAME" and "DB_PASSWORD", and return them to the configuration rendering plugin.

[0076] After receiving the target information, the configuration rendering plugin may add the input parameters of the privacy computing application and the target information to the corresponding fields in the startup configuration template respectively. Specifically, replace the placeholder X corresponding to the field value of field A (i.e., the field corresponding to the dynamic configuration information) in the startup configuration template with the input parameters, and replace the placeholder Y corresponding to the field value of field B (i.e., the field corresponding to the static configuration information) in the startup configuration template with the target information. In this way, the final configuration information is obtained.

[0077] In the above example, the content of the final configuration information may be as follows:

[0078] "task_id":"{'xxxxxxx'}",

[0079] "task_conf ig":"{task-examp l e}",

[0080] "user_name":{zhangsan}

[0081] "db_password":{123456}

[0082] Among them, the field values of the latter two fields are obtained by reading from the configuration management service.

[0083] Step S210, the load management service starts the privacy computing application based on the configuration information received from the configuration rendering plugin.

[0084] Among them, when the second party has created a Pod, the load management service can mount the received final configuration information into the created Pod, and in this Pod, based on the final configuration information, pull up the application container of the privacy computing application. Thus, the startup of the privacy computing application is completed.

[0085] Of course, in practice, the above privacy computing application can also be started in the way of Docker or directly on bare metal, which is not limited in this specification.

[0086] Thus, the startup of the privacy computing application in the second party is completed, that is, the privacy computing application is started in the organization where the second party is deployed. It should be understood that after the privacy computing application is started in each organization where the second party is deployed, multiple organizations can jointly execute privacy computing.

[0087] In summary, the present solution has the following innovative points:

[0088] 1. Separate the dynamic configuration information and static configuration information of the privacy computing application. Among them, the dynamic configuration information is sent by the task initiator, and the static configuration information for configuring the privacy computing application is locally maintained by the participating party, and the sensitive information is entrusted by the key escrow service, so as to avoid the leakage of sensitive information of the participating party.

[0089] 2. The configuration management service of the participating party divides the static configuration information of the privacy computing application into non-sensitive information and sensitive information, which can effectively manage the static configuration information of the privacy computing application.

[0090] 3. The startup configuration template and dynamic configuration information of the privacy computing application are indirectly passed to the load management service of the participating party through the ConfigMap resource or Pod resource. The load management service calls the configuration rendering plugin, parses the startup configuration template, obtains the placeholders in the startup configuration template, and obtains the static configuration information corresponding to the placeholders from the configuration management service. Finally, the dynamic configuration information and static configuration information are rendered into the startup configuration template. Through this method, the privacy computing application does not need to actively obtain the dependent static configuration information and dynamic configuration information in different ways, nor does it need to perceive the difference between the static configuration information and the dynamic configuration information. It only needs to load the mounted final configuration information and start normally, thus reducing the understanding cost.

[0091] Corresponding to the above application startup method based on Kubernetes, an embodiment of this specification also provides a Kubernetes-based application startup system, as Figure 3 shown, this system may include: including a first party 302 and a second party 304, among which,

[0092] The first party 302 is used to create a first resource in the namespace of the second party 304 in the Kubernetes cluster it belongs to according to the start instruction of the privacy computing application. This first resource is used to store the input parameters and start configuration template of the privacy computing application.

[0093] The second party 304 is used to monitor the creation of the first resource in its own namespace, read the target information pre-registered for the privacy computing application from the local, and fill the input parameters and the target information into the start configuration template correspondingly to obtain the configuration information of the privacy computing application.

[0094] The second party 304 is also used to start the privacy computing application based on the configuration information.

[0095] The functions of the parties involved in the system in the above embodiments of this specification can be implemented by the steps in the above method embodiments. Therefore, the specific working process of the system provided in an embodiment of this specification will not be elaborated here.

[0096] The Kubernetes-based application start system provided in an embodiment of this specification can start the privacy computing application simply and quickly.

[0097] Corresponding to the above Kubernetes-based application start method, an embodiment of this specification also provides a Kubernetes-based application start device, which is set in the second party. As Figure 4 shown, this device includes:

[0098] A reading unit 402 is used to monitor that the first party creates a first resource in the namespace of the second party in the Kubernetes cluster it belongs to, and read the target information pre-registered for the privacy computing application. This first resource is used to store the input parameters and start configuration template of the privacy computing application.

[0099] A generating unit 404 is used to fill the input parameters and the target information into the start configuration template correspondingly to obtain the configuration information of the privacy computing application.

[0100] A starting unit 406 is used to start the privacy computing application based on the above configuration information.

[0101] In one embodiment, the above start configuration template includes a first field corresponding to the target information;

[0102] The reading unit 402 includes:

[0103] A parsing sub-module 4022 is used to parse the start configuration template to obtain the field name of the first field;

[0104] A reading sub-module 4024, configured to read target information according to the field name of the first field.

[0105] In one embodiment, the above-mentioned target information includes sensitive information, and the reading sub-module 4024 is specifically configured to:

[0106] Read sensitive information from the key escrow service according to the target field name corresponding to the sensitive information.

[0107] In one embodiment, the above-mentioned startup configuration template includes a first field corresponding to the target information and a second field corresponding to the input parameter;

[0108] The generating unit 404 is specifically configured to:

[0109] Correspondingly add the input parameter and the target information to the first field and the second field in the startup configuration template respectively.

[0110] In one embodiment, the starting unit 406 is specifically configured to:

[0111] Mount the configuration information to the target pod, and in the target pod, pull up the application container corresponding to the privacy computing application based on the configuration information.

[0112] In one embodiment, the number of the above-mentioned first resources is two, and the two first resources are respectively used to store the input parameter and the startup configuration template.

[0113] In a more specific embodiment,

[0114] Both of the above two first resources are ConfigMap resources; or,

[0115] Both of the above two first resources are Pod resources; or,

[0116] One of the above two first resources is a ConfigMap resource, and the other is a Pod resource.

[0117] The functions of the functional units of the device in the above-mentioned embodiments of this specification can be implemented by the steps of the above-mentioned method embodiments. Therefore, the specific working process of the device provided by an embodiment of this specification will not be repeated here.

[0118] The application startup device based on Kubernetes provided by an embodiment of this specification can start the privacy computing application simply and quickly.

[0119] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute the method described in conjunction with Figure 2 ...

[0120] According to an embodiment of still another aspect, there is also provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in conjunction with Figure 2 is implemented.

[0121] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the medium or device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the partial description of the method embodiments for the relevant parts.

[0122] The steps of the method or algorithm described in conjunction with the disclosure of this specification can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules. The software modules can be stored in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. Additionally, the ASIC can be located in a server. Of course, the processor and the storage medium can also exist as discrete components in the server.

[0123] Those skilled in the art should be able to realize that in the above one or more examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium facilitating the transmission of a computer program from one place to another. The storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0124] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0125] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of this specification. It should be understood that the above description is only the specific embodiments of this specification and is not used to limit the protection scope of this specification. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of this specification shall be included within the protection scope of this specification.

Claims

1. A Kubernetes-based application startup method, involving a first party and a second party, wherein the first party is deployed with a task scheduling service, and the second party is deployed with a load management service, a configuration rendering plug-in, and a configuration management service; the method comprises: The task orchestration service creates a first resource in the namespace of the second party in the Kubernetes cluster to which it belongs according to the startup instruction of the privacy computing application, where the first resource is used to store input parameters and a startup configuration template of the privacy computing application; The load management service monitors the creation of the first resource under the namespace of the second party, and sends a call instruction to the configuration rendering plug-in; The configuration rendering plug-in reads the target information pre-registered for the privacy computing application from the configuration management service, and fills the input parameters and the target information into the startup configuration template accordingly to obtain the configuration information of the privacy computing application; The load management service starts the privacy computing application based on the configuration information received from the configuration rendering plug-in.

2. The method according to claim 1, wherein: The startup configuration template includes a first field corresponding to the target information; the calling instruction includes the input parameter and the startup configuration template; The configuration rendering plug-in reads target information pre-registered for the privacy computing application from the configuration management service, including: The configuration rendering plug-in parses the startup configuration template to obtain the field name of the first field; The configuration rendering plug-in reads the target information from the configuration management service according to the field name of the first field.

3. The method according to claim 2, wherein: The target information includes sensitive information; and the target information is read from the configuration management service, including: The configuration rendering plug-in sends a read instruction to the configuration management service, including the target field name corresponding to the sensitive information; The configuration management service reads the sensitive information from the key escrow service according to the target field name; The configuration management service sends the sensitive information to the configuration rendering plug-in.

4. The method according to claim 1, wherein: The startup configuration template includes a first field corresponding to the target information and a second field corresponding to the input parameter; Filling the input parameters and target information into the startup configuration template accordingly includes: The input parameters and target information are added to the first field and the second field in the startup configuration template respectively.

5. The method according to claim 1, wherein: The starting the privacy computing application includes: The load management service mounts the configuration information into the target pod, and in the target pod, pulls up the application container corresponding to the privacy computing application based on the configuration information.

6. The method according to claim 1, wherein: The number of the first resources is two, and the two first resources are used to store the input parameters and the startup configuration template respectively.

7. The method according to claim 6, wherein: The two first resources are both ConfigMap resources; or, The two first resources are both Pod resources; or, One of the two first resources is a ConfigMap resource, and the other is a Pod resource.

8. A Kubernetes-based application startup method, involving a first party and a second party, wherein the second party is deployed with a load management service, a configuration rendering plug-in, and a configuration management service; the method comprises: The load management service monitors that the first party creates a first resource under the namespace of the second party in the Kubernetes cluster to which the first party belongs, and sends a call instruction to the configuration rendering plug-in; The first resource is used to store input parameters and startup configuration templates of the privacy computing application; The calling instruction is used to instruct the configuration rendering plug-in to read the target information pre-registered for the privacy computing application from the configuration management service, and fill the input parameters and the target information into the startup configuration template accordingly to obtain the configuration information of the privacy computing application; The load management service starts the privacy computing application based on the configuration information received from the configuration rendering plug-in.

9. A Kubernetes-based application startup system, comprising a first party and a second party; The first party is used to create a first resource under the namespace of the second party in the Kubernetes cluster to which it belongs according to the startup instruction of the privacy computing application, where the first resource is used to store input parameters and a startup configuration template of the privacy computing application; The second party is used to monitor the creation of the first resource under the namespace of the second party, read the target information pre-registered for the privacy computing application from the local, and fill the input parameters and the target information into the startup configuration template accordingly to obtain the configuration information of the privacy computing application; The second party is further used to start the privacy computing application based on the configuration information.

10. A Kubernetes-based application startup device, disposed on a second party; the device comprises: A reading unit, configured to monitor that the first party creates a first resource under the namespace of the second party in the Kubernetes cluster to which the first party belongs, and read target information pre-registered for the privacy computing application; The first resource is used to store input parameters and startup configuration templates of the privacy computing application; A generating unit, configured to fill the input parameters and target information into the startup configuration template accordingly to obtain configuration information of the privacy computing application; A starting unit is used to start the privacy computing application based on the configuration information.

11. The device according to claim 10, wherein: The startup configuration template includes a first field corresponding to the target information; The reading unit comprises: A parsing submodule, used to parse the startup configuration template to obtain the field name of the first field; A reading submodule is used to read the target information according to the field name of the first field.

12. The device according to claim 11, wherein The target information includes sensitive information; the reading submodule is specifically used for: The sensitive information is read from a key escrow service according to a target field name corresponding to the sensitive information.

13. The device according to claim 10, wherein: The startup configuration template includes a first field corresponding to the target information and a second field corresponding to the input parameter; The generating unit is specifically used for: The input parameters and target information are added to the first field and the second field in the startup configuration template respectively.

14. The device according to claim 10, wherein: The startup unit is specifically used for: The configuration information is mounted into the target pod, and in the target pod, based on the configuration information, an application container corresponding to the privacy computing application is pulled up.

15. The device according to claim 10, wherein: The number of the first resources is two, and the two first resources are used to store the input parameters and the startup configuration template respectively.

16. The device according to claim 15, wherein: The two first resources are both ConfigMap resources; or, The two first resources are both Pod resources; or, One of the two first resources is a ConfigMap resource, and the other is a Pod resource.

17. A computer-readable storage medium having a computer program stored thereon, wherein: When the computer program is executed in a computer, the computer is caused to execute the method according to any one of claims 1 to 8.

18. A computing device comprising a memory and a processor, wherein: The memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • API gateway service updating method and device

    CN110493067A

  • Container application deployment method and device, electronic equipment and storage medium

    CN112346818A

  • Static resource processing method and device, computer equipment and storage medium

    CN113326081A

  • Webpage rendering method and device, electronic equipment and computer readable storage medium

    CN113468456A

  • Data information distribution method and device, electronic equipment and storage medium

    CN114675974A