Method and system for measuring release integrity of container application
By evaluating the integrity of container images and preheating, the security problem of container images being tampered with is solved, ensuring the security of container clusters and hosts, and reducing startup time.
Patent Information
- Application Number
- CN202311865709.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
The prior art lacks a method for measuring the integrity of container images, which may be illegally tampered with, which in turn causes malicious programs to run on the host and raises security risks.
The integrity measurement module is used to measure the container image, generate the first measurement result and store it, and combine the access controller to compare the first and second measurement results when the container is created. If it is consistent, the creation process will continue. Otherwise, it will be interrupted and the container image warm-up function will be used to reduce the startup time.
Effectively protect the security of container clusters and hosts, avoid illegally tampered container images running on the host, reduce security risks, and improve the security of container technology use.
Smart Images

Figure CN120234093A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of container cloud, and in particular, to a method and system for measuring the integrity of container application publishing. Background Art
[0002] Container technology is a lightweight operating system virtualization technology. Containers package application programs and their dependencies into a lightweight and portable runtime environment, allowing developers to consistently build, deploy, and run application programs in different environments. Compared with traditional virtual machines, containers run directly in the operating system, offering higher performance, better portability, and faster speed. Kubernetes (hereinafter referred to as k8s) is used to manage and orchestrate containerized applications on multiple hosts in a cloud platform. In K8s, multiple containers can be created, with each container running an application instance. Then, through built-in load balancing strategies, the management, discovery, and access of a group of application instances are achieved.
[0003] One of the main obstacles to the widespread deployment of containers is the security issues they face, one of which is the unauthorized escape behavior of containers. The possible reason for this behavior is that the container image and its internal programs are illegally tampered with after being built and malicious programs are implanted. When using such container images to create container applications on a host, the malicious programs may be exploited by the host or external attackers. The attackers may obtain access privileges to the container, thereby obtaining specific permissions of the host, breaking through the normal isolation environment restrictions, and using some means to obtain the ability to execute commands under a certain permission of the direct host where the container is located, other containers on the host, or other hosts and other containers within the cluster, for malicious attacks or unauthorized access.
[0004] Therefore, to ensure the security and integrity of container images without tampering, a method for measuring the integrity of container images is needed to prevent containers from being illegally tampered with and ensure that container applications are started using untampered container images.
[0005] Moreover, in the prior art, developers mostly use K8s for container orchestration, and the container images are not verified during the standard container application publishing process, which may lead to the startup of container applications with tampered container images. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a method and system for measuring the integrity of container application publishing to eliminate or improve one or more defects existing in the prior art.
[0007] One aspect of the present invention provides a method and system for measuring the integrity of container application publishing. The method is implemented using an integrity measurement module that supports integrity measurement and container image preheating. The method includes the following steps:
[0008] Use the integrity measurement module to perform integrity measurement on the constructed container image to obtain the first measurement result, and store the name, label, and the first measurement result of the container image in the measurement result database;
[0009] When using the application container engine to create a container based on the container image on the node to be scheduled, parse the name and label of the container image from the request for creating the container, and send a measurement request including the name and label of the container image to the measurement result database to request the first measurement result;
[0010] On the node to be scheduled for creating a container based on the container image, call the integrity measurement module to perform container image preheating, and use the integrity measurement module to perform integrity measurement on the container image on the local node of the node to obtain the second measurement result;
[0011] Compare the first measurement result and the second measurement result, and perform integrity measurement verification according to the preset standard. If it passes, continue the container creation process; if it does not pass, interrupt the container creation process.
[0012] In some embodiments of the present invention, the integrity measurement refers to the integrity measurement performed on the file system, metadata, layer size, and layer dependency table included in each layer of data of the container image.
[0013] In some embodiments of the present invention, the implementation of the method also utilizes an admission controller. The method uses the application container engine to schedule nodes on a pre-selected container cluster management system and create containers on the nodes based on the container image. The implementation of the method includes:
[0014] When using the application container engine to create a container based on the container image on the node to be scheduled, the API Server component of the container cluster management system receives the request for creating the container, and authenticates and authorizes the request for creating the container;
[0015] After passing the authentication and authorization, use the admission controller to parse the name and label of the container image from the request for creating the container, and use the admission controller to generate a measurement request including the name and label of the container image to the measurement result database to request the first measurement result.
[0016] In some embodiments of the present invention, the admission controller runs in the API Server component of the container cluster management system, and uses the API Server component to compare the first measurement result and the second measurement result.
[0017] In some embodiments of the present invention, the method further includes scheduling nodes using a Docker engine on a K8s system and creating containers on the nodes based on container images; wherein the K8s system includes an API Server component, a Controller Manager component, a label selector, a scheduler component, and a Kubelet component;
[0018] The method further comprises:
[0019] When the replica set controller managed by the Controller Manager component listens to a container creation request based on the list-watch mechanism, and finds through the label selector that the current state of the container group associated with this container creation request in the cluster is inconsistent with the expected state - the number of replicas, it will coordinate operations and initiate a container group creation request to the API Server component;
[0020] The scheduler component uses the list-watch mechanism to discover unbound container groups, and calculates the final schedulable nodes of the container group through the pre-selected node optimization strategy algorithm;
[0021] When the Kubelet component discovers that a new container group is bound to this node based on the list-watch mechanism, it will initiate the process of creating the container group, and the container application is released.
[0022] In some embodiments of the present invention, the integrity metric check of the preset standard refers to comparing whether the first metric result and the second metric result are consistent, and the first metric result and the second metric result are recorded in the form of hash values;
[0023] The method also includes: after passing the integrity measurement verification, updating the data of the container image to the Etcd database of the K8s system through the API Server component.
[0024] In some embodiments of the present invention, the container image preheating step is implemented using OpenKruise technology;
[0025] The admission controller is used to intercept container creation requests that fail to pass the integrity measurement check before updating the container image data to the Etcd database of the K8s system.
[0026] Another aspect of the present invention provides a container application publishing integrity measurement system, including a processor and a memory, wherein the memory stores computer instructions, and the processor is used to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the system implements the steps of the method described in any one of the above embodiments.
[0027] On the other hand, the present invention provides a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the steps of the method described in any one of the above embodiments are implemented.
[0028] On the other hand, the present invention provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in any one of the above embodiments are implemented.
[0029] The method and system for measuring the integrity of container application release proposed by the present invention can generate a first measurement result and a second measurement result based on the container image integrity measurement module, improve the container creation process, introduce integrity measurement verification in the container creation process to avoid running illegally tampered container images on the host, effectively protect the security of the container cluster and the host, and thus to a certain extent solve the security risks that may be brought by the running of illegal programs in the container on the host, and minimize the damage caused thereby.
[0030] The additional advantages, objects, and features of the present invention will be partially described below, and will become partially apparent to those of ordinary skill in the art after studying the following, or can be learned from the practice of the present invention. The objects and other advantages of the present invention can be realized and obtained by the structure specifically pointed out in the specification and the drawings.
[0031] Those skilled in the art will understand that the objects and advantages that can be achieved by the present invention are not limited to the above specifically described, and the above and other objects that the present invention can achieve will be more clearly understood according to the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The drawings described herein are used to provide a further understanding of the present invention, form a part of this application, and do not limit the present invention. In the drawings:
[0033] Figure 1 It is a flowchart of the method for measuring the integrity of container application release in an embodiment of the present invention.
[0034] Figure 2 It is a flowchart of the integrity measurement for container application release in a specific embodiment of the present invention.
[0035] Figure 3 It is a flowchart of the integrity measurement access control in an embodiment of the present invention.
[0036] Figure 4 It is a schematic diagram of the container image integrity measurement in an embodiment of the present invention.
[0037] Figure 5 It is a flowchart of the container image preheating in an embodiment of the present invention. Detailed implementation mode
[0038] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below in conjunction with the implementation modes and the accompanying drawings. Herein, the illustrative implementation modes of the present invention and their descriptions are used to explain the present invention, but do not limit the present invention.
[0039] Herein, it should also be noted that in order to avoid obscuring the present invention due to unnecessary details, only the structures and / or processing steps closely related to the solution of the present invention are shown in the drawings, while other details less related to the present invention are omitted.
[0040] It should be emphasized that the term "comprising / including" as used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.
[0041] Herein, it should also be noted that if not otherwise specified, the term "connection" in this article can not only refer to direct connection, but also represent indirect connection with intermediaries.
[0042] The concepts related to container application publishing and K8s platform components used in the present invention are summarized as follows:
[0043] (1) Container: It is a virtualization technology at the operating system level. It packages an application program and its dependencies in a container and deploys it on the operating system kernel of the host.
[0044] (2) Container image: It refers to a packaging format used in containerization technology. It contains the complete application program and all components and dependencies required for its operation. A container image can be regarded as an executable software package, which contains the code of the application program, the runtime environment, library files, configuration files, etc.
[0045] (3) Docker: It is an open-source application container engine that allows developers to package their application programs and their dependencies into a portable image, and then publish it to any machine with a popular Linux or Windows operating system, and virtualization can also be achieved. The workflow of using Docker: Configure the website and the required environment, package them into a package (Docker image), then install Docker on the server, use Docker to pull the packaged container image, and the container can run directly without repeated configuration, which is more convenient for management. After modifying the configuration in the image, update the container image in Docker, and the modification or update of the website can be completed.
[0046] (4) Container Cluster Management System (Kubernetes): Abbreviated as K8s, it is an open-source system used to manage containerized applications on multiple hosts in a cloud platform. The goal of Kubernetes is to make it simple and efficient to deploy containerized applications. Kubernetes provides a mechanism for application deployment, planning, updating, and maintenance. It orchestrates multiple containers and multiple nodes through a series of schedulers, etc. A docker runs on each node, and containers are created within the docker.
[0047] (5) Api server: One of the K8s components, it provides HTTP Rest interfaces such as create, delete, update, query, and watch for various resource objects (Pods, RCs, Services, etc.) in K8s, and is the data bus and data center of the entire system.
[0048] (6) Controller Manager: One of the K8s components, as the management and control center within the cluster, it is responsible for the management of resources such as Nodes, Pod replicas, service endpoints (Endpoints), and namespaces (Namespaces) in the cluster. When a certain Node fails unexpectedly, the Controller Manager will detect it in time and execute an automated repair process to ensure that the cluster is always in the expected working state.
[0049] (7) Scheduler: One of the K8s components, responsible for allocating new Pods to appropriate nodes (Nodes) according to the scheduling strategy.
[0050] (8) Kubelet: One of the K8s components, it is the main service on the worker node. It regularly receives new or modified container group specifications from the Api server component and ensures that the container group and the containers it contains run under the expected specifications. At the same time, as a monitoring component of the worker node, it reports the running status of the host to the Api server.
[0051] (9) Etcd: One of the K8s components, it is a distributed key-value storage system, which is widely used to store configuration information, metadata, status data, etc. in the cluster.
[0052] (10) Pod (Container Group): The smallest unit in the K8s cluster, it is a combination of containers and serves as the running unit of the application.
[0053] In the following, embodiments of the present invention will be described with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar components, or the same or similar steps.
[0054] The main defects of the prior art are as follows: (1) There is a lack of a measurement method for verifying the integrity of container images; (2) The native K8s container application release process does not target container image verification. Therefore, the present invention proposes a method and system for measuring the integrity of container application releases. The main improvement directions of the method proposed by the present invention mainly include: (1) proposing a method for measuring the integrity of container images; (2) integrating the proposed method for measuring the integrity of container images into the container application release process; (3) the proposed container image integrity measurement module has a container image preheating function to reduce the application startup time.
[0055] The file system of a container image adopts a layered concept. A container image is a "collection of layers" that has been encapsulated. Among various images, the base image is relatively special. It is a pure Linux distribution image that only contains the root file system (rootfs), that is, the Linux file system. It should be noted that a complete rootfs is not necessarily just one layer. It may be composed of multiple layers together. In other non-base images, in addition to the root file system (rootfs), there are also some other layers and metadata. The metadata stores relevant information about the image, such as the image id, creation time, etc. These layers and metadata together constitute the image.
[0056] Taking the Docker container engine as an example, when Docker extracts a container image, first, each layer of the image is extracted to the corresponding directory, then the size and metadata of each layer are extracted to the corresponding directory, and finally, the layer dependency relationship (all the parent layers of this layer) is written into a specified file. From this, it can be seen that each layer of data of a container image includes the file system, metadata, layer size, and layer dependency relationship table. The corresponding directories on the host are / docker / aufs / diff / id, / docker / graph / id, and / docker / aufs / layers / id respectively. The container image integrity measurement mainly targets these layered files.
[0057] For the characteristics of the container images stated above, the designed container image integrity measurement module needs to have a container image measurement function to measure the integrity of container images, a container image preheating function to reduce the application startup time, and a measurement value storage function. It runs on the worker nodes of the K8s system in the form of a daemonset.
[0058] The specific design idea of the container image integrity measurement method based on the container image integrity measurement module and the Api-server admission controller is as follows:
[0059] First, after the container image is built, use the container image measurement function of the container image integrity measurement module to measure the container image. After the measurement is completed, store the result in the database as the reference value for subsequent integrity measurement.
[0060] Secondly, for the process of container application publishing, design an Api-server admission controller. When creating a container, send the container image name and label to the container image integrity measurement module to obtain the measurement value, and measure the local image of the node based on the image information and node information. If the container image does not exist on the node, preheat the image and then calculate the measurement value of the image. Compare the two measurement values and return them to the api-server. If the verification passes, the api-server continues to create the container; otherwise, it is interrupted.
[0061] Figure 1 It is a flowchart of the integrity measurement method for container application publishing in an embodiment of the present invention. The method is implemented by using an integrity measurement module that supports integrity measurement and container image preheating. The method includes the following steps:
[0062] Step S110: Use the integrity measurement module to perform integrity measurement on the built container image to obtain the first measurement result, and store the name, label, and first measurement result of the container image in the measurement result database.
[0063] Step S120: When creating a container based on a container image on a node to be scheduled using an application container engine, parse the name and label of the container image from the container creation request, and send a measurement request containing the name and label of the container image to the measurement result database to request the first measurement result.
[0064] In the specific implementation process, if the request for the first measurement result fails, it means that there is no integrity measurement result of the corresponding container image in the measurement result database, and an error signal is returned to prompt the user to reconfirm information such as the name and label of the container image.
[0065] Step S130: On the node to be scheduled for creating a container based on a container image, call the integrity measurement module to perform container image preheating, and use the integrity measurement module to perform integrity measurement on the local container image of the node to obtain the second measurement result.
[0066] Step S140: Compare the first measurement result and the second measurement result, and perform integrity measurement verification according to a preset standard. If it passes, continue the container creation process; if it does not pass, interrupt the container creation process.
[0067] By adopting the embodiments of the present invention, the first measurement result and the second measurement result can be generated based on the container image integrity measurement module, which improves the container creation process. Integrity measurement verification is introduced in the container creation process to prevent illegally tampered container images from running on the host, effectively protecting the security of the container cluster and the host, thus solving to a certain extent the security risks that may be brought by the running of illegal programs in the container on the host and minimizing the damage caused thereby.
[0068] In some embodiments of the present invention, the integrity measurement refers to the integrity measurement performed on the file system, metadata, layer size, and layer dependency table included in each layer of data of the container image.
[0069] In the specific implementation process, the algorithms that can be selected for integrity measurement include the sha-2 algorithm. Specifically, the hash values of each part of the container image can be calculated separately and then concatenated, and then a sha-2 calculation is performed again. The finally obtained hash value is used as the reference value and stored in the measurement result database (or can be called the measurement value storage database). The present invention is not limited thereto, and the integrity measurement algorithms that can be adopted can be replaced.
[0070] Figure 4 This is the schematic diagram of the container image integrity measurement principle in an embodiment of the present invention. Figure 4 The middle is the principle schematic of using the sha-2 algorithm for integrity measurement. For CMD, VOLUME,..., FROM, a hash value is calculated respectively based on the sha-2 algorithm, the hash values are concatenated, and then a sha-2 algorithm calculation is performed again to obtain the final measurement result (also called the measurement value). Optionally, the measurement value can be a hash value, but it is not limited thereto.
[0071] By adopting the embodiments of the present invention, the construction of the integrity measurement module can be realized, and the integrity measurement module is used to perform integrity measurement on the container image.
[0072] In some embodiments of the present invention, the implementation of the method also utilizes an admission controller. The method schedules nodes on a pre-selected container cluster management system using an application container engine and creates containers on the nodes based on the container image. The steps include:
[0073] (1) When creating a container on a node to be scheduled based on the container image using the application container engine, the API Server component of the container cluster management system receives the request to create a container and authenticates and authorizes the request to create a container.
[0074] Optionally, in the specific implementation process, the authentication is kubeconfig authentication.
[0075] (2) After passing the authentication and authorization, the admission controller is used to parse the name and tag of the container image from the request for creating a container, and the admission controller is used to generate a metric request including the name and tag of the container image to the metric result database to request the first metric result. It should be noted that the node for performing integrity metric detection after authentication and authorization proposed in the embodiments of the present invention is only an example, and the present invention is not limited thereto. The integrity metric process for container application publishing can be performed at other nodes in the container application publishing process.
[0076] In the specific implementation process, the container image integrity metric user requests the API Server (interface / gateway, responsible for the communication of each functional module of the cluster) to create a replicaset - replication controller - multiple replica pods - create multiple containers (replicasets) through the API or the client. After passing authentication and authorization, the Api Server component enters the integrity metric admission control. This step adopts integrity metric admission control. First, the container image in the request is parsed, and a metric request is sent to the integrity metric module. The integrity metric module will query its database to check if there is integrity metric information for the container image. Otherwise, an error signal is returned. The admission control module receives this signal. If there is no integrity metric information, the creation process is aborted. If there is metric information, it carries this information and continues the creation process, and persists the request-related information to the Etcd database.
[0077] By adopting the embodiments of the present invention, based on the pre-built admission controller, in the container application publishing process, the integrity metric of the container image is introduced, thus preventing a tampered container image from passing through the container application publishing process and entering the container, which may affect the information security of the host.
[0078] Further, in an embodiment of the present invention, the admission controller runs in the APIServer component of the container cluster management system, and the API Server component is used to compare the first metric result and the second metric result.
[0079] By adopting the embodiments of the present invention, it provides integrity metric based on the Docker tool using the API Server component in the K8s system, so as to check whether the container image has been tampered with.
[0080] In a specific embodiment of the present invention, the method further includes scheduling nodes using the Docker engine on the K8s system and creating containers based on the container image on the nodes; wherein, the K8s system includes an API Server component, a Controller Manager component, a label selector, a scheduler component, and a Kubelet component.
[0081] Furthermore, in the embodiment of the invention, the method also includes: (1) when the replica set controller managed by the Controller Manager component listens to a container creation request based on the list-watch mechanism, and finds through the label selector that the current state of the container group associated with this container creation request in the cluster is inconsistent with the expected state - the number of replicas, it will perform a coordination operation and initiate a container group creation request to the API Server component; (2) using the scheduler component to discover unbound container groups based on the list-watch mechanism, and calculate the final schedulable node of the container group through the pre-selected node optimization strategy algorithm; (3) using the Kubelet component to discover based on the list-watch mechanism that a new container group is bound to this node, it will initiate the relevant process of creating the container group, and the container application release is completed.
[0082] In the specific implementation process, the replica set controller managed by the Controller Manager management control center listens to the request to create multiple containers (replicasets) through the list-watch mechanism, and finds through the label selector that the current state of the container group associated with this multiple container (replicasets) in the cluster is inconsistent with the expected state-number of copies, and then performs a coordination operation (reconcile) to initiate a request to create a container group to the API Server component. The present invention is not limited to this, and the above container creation steps can be replaced.
[0083] By adopting the embodiment of the invention, the nodes used to create containers can be scheduled based on the list-watch mechanism and the various components included in the K8s system. This step is actually a technical problem that can be solved and overcome by those skilled in the art.
[0084] In some embodiments of the present invention, the integrity measurement check of the preset standard refers to comparing whether the first measurement result and the second measurement result are consistent, and the first measurement result and the second measurement result are recorded in the form of hash values.
[0085] Furthermore, the method also includes: after passing the integrity measurement verification, updating the data of the container image to the Etcd database of the K8s system through the API Server component.
[0086] By adopting the embodiment of the invention, container image data can be synchronized in the K8s system through the API Server component to avoid system anomalies that may be caused by data asynchrony.
[0087] In some embodiments of the present invention, the container image preheating step is implemented using OpenKruise technology.
[0088] In some embodiments of the present invention, the access controller is configured to intercept a container creation request that fails to pass the integrity measurement verification before updating the data of the container image to the Etcd database of the K8s system.
[0089] By adopting the embodiments of the present invention, it is possible to screen whether the container image used to create the container application has been tampered with, and make every effort to ensure the information security on the host side.
[0090] Figure 2 It is a flow chart of container application release integrity measurement in a specific embodiment of the present invention. The user requests the API Server component (which is used to manage the communication of each functional module of the cluster) to create a replicaset - replica controller - multiple replica pods - create multiple containers (replicasets) through the API or the client. After authentication and authorization, the API Server component enters the integrity measurement admission control. In this step, integrity measurement admission control is adopted. First, the container image in the request is parsed, and a measurement request is sent to the integrity measurement module. The integrity measurement module will query whether there is integrity measurement information of the container image in its database. Otherwise, an error signal is returned. The admission control module receives this signal. If there is no integrity measurement information, the creation process is aborted. If there is measurement information, the information is carried and the creation process continues, and the request-related information is persisted to the Etcd database.
[0091] The replicaset controller managed by the Controller Manager management control center, based on the list-watch mechanism, monitors that there are multiple container (replicasets) creation requests. If it is found through the label selector that the current state of the container group associated with this multiple container (replicasets) creation request in the cluster is inconsistent with the expected state - the number of replicas, a reconciliation operation will be performed to send a request to create a container group to the API Server component. Among them, the List-watch mechanism is a relatively common distributed coordination mechanism, which enables multiple nodes in the system to communicate with each other and synchronize the updated state. The basic principle of the List-watch mechanism is that a node A publishes a list to the shared memory, and then another node B can access the stored list. When A makes any changes to the stored list, the system will automatically notify node B to synchronize the data.
[0092] Further, the Scheduler discovers unbound Pods based on the list-watch mechanism, calculates the nodes to which the Pods can be finally scheduled through the preselected node preference strategy algorithm. At this time, it calls the mirror preheating function of the integrity measurement module to preheat the mirror on the node to be scheduled. After the preheating is completed, the integrity measurement service of the node measures it, and compares the measurement result with the measurement value carried in the request. If they are inconsistent, the integrity measurement check fails and the creation process is aborted. If the measurement values are consistent, the check passes, and the data is updated to the Etcd database through the API Server component to continue the subsequent creation process.
[0093] Finally, when the Kubelet component discovers that a new Pod is bound to this node based on the list-watch mechanism, it will initiate the process related to creating the Pod, and thus complete the container application release.
[0094] Figure 2 It includes the following steps:
[0095] (1) The user uses the kubectl command or calls the API to initiate a request to create a Pod.
[0096] (2) Perform kubeconfig authentication on the container image.
[0097] (3) If the authentication fails, the process ends; if the authentication passes, continue to the next step.
[0098] (4) Enter the admission control of the API Server component, parse the container image parameters in the request, and initiate a request to the integrity measurement module to verify whether there is measurement information for the image name. If there is, the measurement information is base64-encoded and stored in the annotation of the container resource template in the form of key-value pairs; otherwise, the admission control check fails.
[0099] (5) If the check fails, the process ends; if the check passes, continue to the next step.
[0100] (6) Persist the request information to the Etcd database. The controller manager component discovers the update of the Pod information through the watch interface of the APIServer component, executes the integration of the topology structure on which the resource depends, and after the integration, hands the corresponding information to the API Server component, and the apiserver writes it to the Etcd database.
[0101] (7) The Scheduler component updates through the watch interface of the API Server component that the container group can be scheduled, assigns nodes to the container group through an algorithm. At this time, it calls the container image preheating function of the integrity measurement module to perform container image preheating on the node to be scheduled. After the preheating is completed, the integrity measurement service of this node measures it, and compares this measurement result with the measurement value carried in the request.
[0102] (8) If the comparison is inconsistent, the process ends; if the comparison result is consistent, proceed to the next step.
[0103] (9) The Scheduler component updates the data to the etcd database through the API Server component to continue the subsequent creation process. The Kubelet component discovers through the list-watch mechanism that a new container group is bound to the node and completes the relevant process of creating the container group.
[0104] (10) End the process.
[0105] Figure 3 This is the flowchart of integrity measurement admission control in an embodiment of the present invention. The API Server component, as the gateway of the container cluster management system (K8s), is the only entry to access and manage resource objects. All the remaining components that need to access cluster resources, including basic cluster components such as Controller Manager, Scheduler, kubelet, and kube-proxy, additional cluster components such as CoreDNS, and the previously used kubectl command, etc., have to access and manage the cluster through this gateway. These clients have to access or change the cluster state and complete data storage via the API Server component, and it conducts legality checks on each access request, including user identity authentication, operation permission verification, and whether the operation conforms to the constraints of global specifications, etc. All checks must be completed normally and the object configuration information must pass the legality check before accessing or storing data in the etcd database.
[0106] The admission controller is used to intercept requests after the client requests have passed authentication and authorization checks but before the object is persistently stored in etcd, and is used to enforce semantic verification of objects during operations such as creating, updating, and deleting resources. Operation requests for reading resource information will not be checked by the admission controller.
[0107] The integrity measurement admission controller process includes two stages: (1) Obtaining the measurement information of the image and modifying the request (Mutating admission). First, parse the container image parameters in the request, and send a request to the integrity measurement module to verify whether there is measurement information for the image name. If there is, return it; otherwise, return a null value. If the measurement information is normally returned, encode the measurement information in base64 and store it in the annotation of the container resource template in key-value pairs, and continue the subsequent verification process. (2) Verifying the request (Validating admission). If the measurement information can be normally obtained in the first step and the measurement value can be obtained in the request, the verification passes; otherwise, the container creation process is interrupted.
[0108] As Figure 3 shown, the method includes the following steps:
[0109] (1) Receive the API request, enter the API HTTP Handler, and perform authentication and authorization.
[0110] (2) Perform mutation (Mutating admission) in the API Server module. Specifically, it includes: parsing the API request, sending a request to the integrity measurement module to verify whether there is a measurement value (i.e., the measurement result) for the specified container image. If there is, append the measurement value to the annotation; otherwise, append a null value.
[0111] (3) Perform object Schema verification.
[0112] (4) Perform the verification step (Validating Admission). Specifically, it is necessary to verify whether there is a measurement value in the annotation. If it exists, the verification passes; otherwise, it fails.
[0113] (5) Store the relevant data in the Etcd database and enter the subsequent container application release process.
[0114] Figure 5 This is the flowchart of container image preheating in an embodiment of the present invention. The container image integrity measurement module supports the container image measurement function and the container image preheating function.
[0115] The principle of container image measurement is as follows: Container images have a layered structure, and each layer contains some files of the file system. When a container starts, these layers are combined into a complete file system. Taking the Docker container engine as an example, the container image data of each layer includes the file system, metadata, layer size, and layer dependency table, corresponding to the directories / docker / aufs / diff / id, / docker / graph / id, and / docker / aufs / layers / id respectively. The container image measurement function measures these image layer files. After downloading the container image to the local (node), the module uses a hashing algorithm such as the sha-2 algorithm to calculate the hash values of each part of the image respectively, connects them, and then performs another sha-2 calculation to obtain the final hash value. This hash value is used as the reference value and stored in the measurement value storage database, such as Figure 4 as shown.
[0116] The principle of the container image preheating function lies in: By obtaining image information and node information in the k8s container creation process, the specified container image is pulled by the container runtime on the specified node for preheating. After preheating, the integrity measurement module measures the container image on the local node of the node and returns the measurement value. The container image preheating process is as Figure 5 shown.
[0117] Figure 5 includes the following steps:
[0118] (1) In the pre - step, the API Server component admission control can obtain the integrity measurement value of the container image.
[0119] (2) The Scheduler can perform node binding according to the scheduling algorithm / scheduling policy.
[0120] (3) Check whether there are schedulable nodes. If not, end the process; if so, proceed to the next step.
[0121] (4) Call the integrity measurement module image preheating API to preheat the container image on the selected node. After preheating, the integrity measurement module measures the integrity of the container image on the local node of the node. After measurement, compare it with the measurement value obtained in the first step.
[0122] (5) Compare the results of the two measurement values. If they are inconsistent, end the process; if they are consistent, proceed to the next step.
[0123] (6) The Scheduler updates the data to the Etcd database through the API Server component and continues with the subsequent creation process. The Kubelet component discovers that a new container group is bound to the node through the list-watch mechanism and completes the relevant process of creating the container group.
[0124] (7) End the process.
[0125] Further, for the calculated metric values, the present invention provides a database for storing the container image metric values. The database can adopt the distributed key-value storage database Etcd. Correspondingly, data access can be performed through tls authentication.
[0126] Correspondingly, the present invention also provides a container application release integrity metric system. The system includes a computer device, which includes a processor and a memory. Computer instructions are stored in the memory, and the processor is used to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the system implements the steps of the method described above.
[0127] The container application release integrity metric method and system proposed by the present invention can generate the first metric result and the second metric result based on the container image integrity metric module, improve the container creation process, introduce integrity metric verification in the container creation process to avoid running illegally tampered container images on the host, effectively protect the security of the container cluster and the host, and thus solve to a certain extent the security risks that may be brought by the running of illegal programs in the container on the host, and minimize the damage caused thereby.
[0128] By adopting some embodiments of the present invention, the container image preheating function supported by the container image integrity metric module can reduce the application startup time. By using the container image integrity metric method proposed by the present invention to perform container image integrity metric during the container application release process, it is possible to avoid illegally tampered programs from passing through the container application release, avoid starting containers with maliciously tampered container images, and thus avoid malicious attacks on the container and the host, and improve the security of using container technology.
[0129] The key points of the present invention are: (1) proposing an integrity metric module and a corresponding integrity metric algorithm for container images; (2) improving the container creation process, introducing container image integrity metric in the container creation process based on K8s, and performing integrity metric on container images at key nodes in the container application release process based on platforms including K8s.
[0130] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described above are implemented. The computer-readable storage medium may be a tangible storage medium, such as a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, floppy disks, hard disks, removable storage disks, CD-ROMs, or any other form of storage medium known in the art.
[0131] An embodiment of the present invention also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the method described in any one of the above embodiments are implemented.
[0132] Those of ordinary skill in the art should understand that the various exemplary components, systems, and methods described in connection with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Specifically, whether to implement in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave on a transmission medium or a communication link.
[0133] It should be clear that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present invention.
[0134] In the present invention, the features described and / or illustrated for one embodiment can be used in the same way or in a similar way in one or more other embodiments, and / or combined with the features of other embodiments or replace the features of other embodiments.
[0135] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the embodiments of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for measuring the release integrity of container applications, characterized in that, The method is implemented by using an integrity measurement module that supports integrity measurement and container image preheating. The method includes the following steps: Use the integrity measurement module to perform integrity measurement on the built container image to obtain a first measurement result, and store the name, label, and first measurement result of the container image in the measurement result database; When using an application container engine to create a container based on a container image on a node to be scheduled, parse the name and label of the container image from the request to create the container, and send a measurement request containing the name and label of the container image to the measurement result database to request the first measurement result; On the node to be scheduled for creating a container based on a container image, call the integrity measurement module to perform container image preheating, and use the integrity measurement module to perform integrity measurement on the container image on the local node of the node to obtain a second measurement result; Compare the first measurement result and the second measurement result, and perform integrity measurement verification according to a preset standard. If it passes, continue the container creation process; if it does not pass, interrupt the container creation process.
2. The method according to claim 1, characterized in that The integrity measurement refers to the integrity measurement performed on the file system, metadata, layer size, and inter-layer dependency table included in each layer of data of the container image.
3. The method according to claim 1, wherein The implementation of the method also uses an admission controller. The method schedules nodes using an application container engine on a pre-selected container cluster management system and creates a container based on a container image on the node. The method includes: When using an application container engine to create a container based on a container image on a node to be scheduled, the API Server component of the container cluster management system receives the request to create the container, and authenticates and authorizes the request to create the container; After passing the authentication and authorization, use the admission controller to parse the name and label of the container image from the request to create the container, and use the admission controller to generate a measurement request containing the name and label of the container image to the measurement result database to request the first measurement result.
4. The method according to claim 3, characterized in that, The admission controller runs in the API Server component of the container cluster management system, and uses the API Server component to compare the first measurement result and the second measurement result.
5. The method according to claim 1, wherein The method also includes scheduling nodes using the Docker engine on the K8s system and creating a container based on a container image on the node; wherein, the K8s system includes an API Server component, a Controller Manager component, a label selector, a scheduler component, and a Kubelet component; The method also includes: When the replica set controller managed by the Controller Manager component monitors a container creation request based on the list-watch mechanism and discovers through the label selector that the current state of the container group associated with this container creation request in the cluster is inconsistent with the desired state - the number of replicas, a coordination operation will be performed, and a container group creation request will be initiated to the API Server component; The scheduler component uses the list-watch mechanism to discover unbound container groups, and calculates the final schedulable nodes of the container group through the pre-selected node optimization strategy algorithm; When the Kubelet component discovers that a new container group is bound to this node based on the list-watch mechanism, it will initiate the process of creating the container group, and the container application is released.
6. The method according to claim 5, wherein The integrity measurement check of the preset standard refers to comparing whether the first measurement result and the second measurement result are consistent, and the first measurement result and the second measurement result are recorded in the form of hash values; The method also includes: after passing the integrity measurement verification, updating the data of the container image to the Etcd database of the K8s system through the API Server component.
7. The method according to claim 6, characterized in that, The container image preheating step is implemented using OpenKruise technology; The admission controller is used to intercept container creation requests that fail to pass the integrity measurement check before updating the container image data to the Etcd database of the K8s system.
8. A container application release integrity measurement system, including a processor and a memory, characterized in that, The memory stores computer instructions, and the processor is used to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the system implements the steps of the method as claimed in any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.