Container scheduling method and device, scheduler and data processing system
By mixing the deployment of secure containers and ordinary containers on the same computing node, and using scheduler unified scheduling and virtual machine resource supplementation, the problem of flexibility and low efficiency of container scheduling is solved, and efficient resource utilization is achieved.
Patent Information
- Application Number
- CN202410003693.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, container scheduling has poor flexibility, low efficiency, and low resource utilization.
By hybrid deployment of different types of containers, including secure containers and ordinary containers on the same compute node, unified scheduling is used by the scheduler, the deployment location is flexibly determined based on container types and resource requirements, and the resources are supplemented by creating virtual machines to ensure sufficient resources.
Improve the flexibility and efficiency of container scheduling, make full use of cloud resources on computing nodes, and reduce resource waste.
Smart Images

Figure CN120256076A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a container scheduling method, device, scheduler, and data processing system. Background Art
[0002] A container is a virtualization technology that enables different application programs to run in a relatively isolated environment. It has the advantages of light weight, fast startup, and easy deployment, and is widely used in the field of cloud computing. Containers can include a first type of container and a second type of container. Currently, in order to ensure the security of containers, the first type of container and the second type of container are deployed on different computing nodes, and the isolation between the first type of container and the second type of container is achieved through physical isolation, and they do not interfere with each other during container scheduling. However, this scheduling method results in poor flexibility, low efficiency, and low resource utilization of container scheduling. Summary of the Invention
[0003] This application provides a container scheduling method, device, scheduler, and data processing system, which solves the problems of poor flexibility, low efficiency, and low resource utilization of container scheduling.
[0004] In a first aspect, a container scheduling method is provided. This method is applied to a cloud platform that is used to manage a computing cluster that provides cloud services, and this computing cluster includes multiple computing nodes. The method includes: first obtaining a request for indicating the deployment of different types of containers, then determining the deployment location of this type of container according to the container type indicated by the request, and deploying the container indicated by the container type at the deployment location.
[0005] Here, the container types indicated by the request include at least one of a first container type or a second container type. Among them, the security isolation of the first type of container indicated by the first container type is higher than that of the second type of container indicated by the second container type. The deployment location of the first type of container and the deployment location of the second type of container are located on the same computing node, and the first type of container is isolated from the second type of container. Exemplarily, the first type of container may include a security container, and the second type of container may include a common container.
[0006] In this way, the scheduler uniformly schedules common containers and security containers. The common containers and security containers can be deployed on the same computing node of the computing cluster, ensuring that the cloud resources on the computing node can be fully utilized and improving resource utilization. Compared with the separate scheduling method of scheduling common containers and security containers separately, in this application, the scheduler uniformly and flexibly schedules common containers and security containers based on the request for indicating the deployment of different types of containers, supports the scenario where common containers and security containers are mixed and deployed on the same computing node, makes container scheduling flexible, and improves the efficiency of container scheduling.
[0007] In a possible implementation, deploying the container indicated by the container type according to the container deployment location includes: deploying the first type of container on a computing node.
[0008] In another possible implementation, deploying the container indicated by the container type according to the container deployment location includes: deploying the second type of container on a virtual machine of a computing node.
[0009] The first type of container (such as a security container) is usually directly deployed on a computing node, while the second type of container (such as a general container) is usually deployed on a virtual machine running on the computing node, that is, deployed on the computing node in a nested virtualization manner. In this way, the first type of container and the second type of container are isolated on the same computing node, and the scheduler can flexibly schedule this type of container based on the container type on the same computing node, improving the efficiency of container scheduling and resource utilization.
[0010] In another possible implementation, the request includes the resource requirements of the container; deploying the container indicated by the container type according to the container deployment location includes: when the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type.
[0011] The resource requirements of the container can include resources such as computing, storage, and network required by the container. The deployment of the container will occupy the resources at the container deployment location. When the remaining resources at the container deployment location are sufficient to meet the resource requirements, there is no need to expand the available resources, and the container indicated by the container type can be directly deployed at the container deployment location, improving the efficiency of container scheduling and resource utilization.
[0012] In another possible implementation, when the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type includes: when the remaining resources of the first virtual machine of the computing node meet the resource requirements, deploying the second type of container on the first virtual machine. Based on the fact that the second type of container (such as a general container) is deployed on a virtual machine running on the computing node, when the remaining resources of the virtual machine are sufficient to meet the resource requirements, there is no need to expand the available resources, and the general container can be directly deployed on the virtual machine, improving the scheduling efficiency of the general container.
[0013] In another possible implementation, after deploying the second type of container on the first virtual machine, the above method further includes: creating a second virtual machine on the computing node under the condition that the remaining resources of the first virtual machine of the computing node are less than the resource threshold.
[0014] The scheduler can set a resource threshold as the "preheating water level" of the resources. When the remaining resources of the first virtual machine of the computing node are less than the resource threshold, a second virtual machine of the required specification is created on the computing node to timely supplement the resources required for deploying the general container, so that the available resources can be maintained above this "preheating water level".
[0015] Thus, idle available resources can be pre-reserved on the virtual machine. The advance preparation of resources is conducive to the scheduler quickly deploying ordinary containers on the second virtual machine after receiving a request to deploy ordinary containers. On the premise of ensuring that the resource capacity required for deploying ordinary containers is sufficient, reserving a certain amount of redundant resources can facilitate the rapid deployment of ordinary containers in the future and improve the scheduling efficiency of ordinary containers.
[0016] In another possible implementation manner, the request includes the resource requirements of the container; deploying the container indicated by the container type according to the container deployment location includes: when the remaining resources of the first virtual machine of the computing node do not meet the resource requirements, creating a second virtual machine on the computing node; and deploying a second type of container on the second virtual machine.
[0017] As the number of deployed ordinary containers increases, the remaining resources of the virtual machines on the computing node will be insufficient, and the remaining resources may not be enough to continue deploying ordinary containers. When the remaining resources of the first virtual machine of the computing node do not meet the resource requirements, the scheduler can create a second virtual machine with the required specifications on the computing node in real time, so as to timely supplement the available resources, facilitate the rapid deployment of ordinary containers, and improve the scheduling efficiency of ordinary containers.
[0018] In another possible implementation manner, when the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type includes: when the remaining resources of the computing node meet the resource requirements, deploying a first type of container. Based on the first type of container (such as an ordinary container) being deployed on the computing node, when the remaining resources of the computing node are sufficient to meet the resource requirements, there is no need to expand the available resources, and the secure container can be directly deployed on the computing node to improve the scheduling efficiency of the secure container.
[0019] In a second aspect, a container scheduling apparatus is provided. The apparatus includes an acquisition module for acquiring a request for container deployment. A scheduling module for determining the container deployment location according to the container type indicated by the request, where the container type includes at least one of a first container type or a second container type. Among them, the security isolation of the first type of container indicated by the first container type is higher than that of the second type of container indicated by the second container type. The deployment location of the first type of container and the deployment location of the second type of container are located on the same computing node, and the first type of container is isolated from the second type of container. A deployment module for deploying the container indicated by the container type according to the container deployment location.
[0020] In a possible implementation manner, when the deployment module deploys the container indicated by the container type according to the container deployment location, it is specifically used for: deploying the first type of container on the computing node.
[0021] In another possible implementation, when the deployment module deploys a container indicated by a container type according to the container deployment location, it is specifically used for: deploying a second type of container to a virtual machine of a computing node.
[0022] In another possible implementation, the request includes the resource requirements of the container; when the deployment module deploys a container indicated by a container type according to the container deployment location, it is specifically used for: when the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type.
[0023] In another possible implementation, when the remaining resources at the container deployment location meet the resource requirements and the deployment module deploys a container indicated by a container type, it is specifically used for: when the remaining resources of the first virtual machine of the computing node meet the resource requirements, deploying a second type of container to the first virtual machine.
[0024] In another possible implementation, after deploying a second type of container to the first virtual machine, the above-mentioned deployment module is further specifically used for: under the condition that the remaining resources of the first virtual machine of the computing node are less than the resource threshold, creating a second virtual machine on the computing node.
[0025] In another possible implementation, the request includes the resource requirements of the container; when the deployment module deploys a container indicated by a container type according to the container deployment location, it is specifically used for: when the remaining resources of the first virtual machine of the computing node do not meet the resource requirements, creating a second virtual machine on the computing node; deploying a second type of container to the second virtual machine.
[0026] In another possible implementation, when the remaining resources at the container deployment location meet the resource requirements and the deployment module deploys a container indicated by a container type, it is specifically used for: when the remaining resources of the computing node meet the resource requirements, deploying a first type of container.
[0027] In a third aspect, a scheduler is provided. The scheduler includes a memory and a processor. The memory is used for storing a set of computer instructions; when the processor, as an execution device in the first aspect or any possible implementation manner of the first aspect, executes the set of computer instructions, it performs the operation steps of the container scheduling method in the first aspect or any possible implementation manner of the first aspect.
[0028] In a fourth aspect, a computing device cluster is provided. The computing device cluster includes at least one computing device. Each computing device includes a scheduler. The scheduler includes a memory and a processor. The memory is used for storing a set of computer instructions; when the processor, as an execution device in the first aspect or any possible implementation manner of the first aspect, executes the set of computer instructions, it performs the operation steps of the container scheduling method in the first aspect or any possible implementation manner of the first aspect.
[0029] In a fifth aspect, a data processing system is provided. The data processing system includes a computing cluster and a scheduler. The computing cluster is used to provide cloud services and includes a plurality of computing nodes. The scheduler includes a memory and a processor. The memory is used to store a set of computer instructions. When the processor, as the execution device in the first aspect or any possible implementation manner of the first aspect, executes the set of computer instructions, it performs the operation steps of the container scheduling method in the first aspect or any possible implementation manner of the first aspect.
[0030] In a sixth aspect, a computer-readable storage medium is provided, including: computer software instructions. When the computer software instructions run in the scheduler, the scheduler is caused to perform the operation steps of the container scheduling method in the first aspect or any possible implementation manner of the first aspect.
[0031] In a seventh aspect, a computer program product is provided. When the computer program product runs on a computing device, the scheduler is caused to perform the operation steps of the container scheduling method in the first aspect or any possible implementation manner of the first aspect.
[0032] For the technical effects brought by any of the design manners in the second aspect to the seventh aspect, reference may be made to the technical effects brought by the first aspect or different design manners in the first aspect, which will not be elaborated here.
[0033] Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A schematic diagram of a container scheduling method provided for the prior art;
[0035] Figure 2 A schematic diagram of the structure of a data processing system provided by the present application;
[0036] Figure 3 A schematic diagram of the flow of a container scheduling method provided by the present application;
[0037] Figure 4 A schematic diagram of the flow of uniformly scheduling ordinary containers and secure containers provided by the present application;
[0038] Figure 5 A schematic diagram of the process of uniformly scheduling ordinary containers and secure containers based on K8S provided by the present application;
[0039] Figure 6 A schematic diagram of the structure of a container scheduling device provided by the present application;
[0040] Figure 7 A schematic diagram of the structure of a computing device provided by the present application;
[0041] Figure 8 A structural schematic diagram of a computing device cluster provided for this application;
[0042] Figure 9 Another structural schematic diagram of a computing device cluster provided for this application. Specific implementation manners
[0043] For the sake of clear and concise description of the following embodiments, the terms related to this application are briefly introduced first:
[0044] A container can enable different application programs to run in a relatively isolated and secure environment to achieve isolation between application programs and isolation between application programs and the external environment. A container is a lightweight virtualization technology, which has the advantages of fast startup, easy deployment and migration, good security and scalability, and is widely used in the field of cloud computing. Usually, containers can include two types: ordinary containers and secure containers.
[0045] Among them, an ordinary container is a process-level container based on Control Group (cgroup). Cgroup can control the upper limits of resources such as computing resources, storage resources, and network resources that a container can use. Ordinary containers share the same operating system kernel and are usually deployed on virtual machines, and virtual machines are deployed on computing devices, that is, nested virtualization deployment.
[0046] A secure container is a container based on a lightweight Virtual Machine (VM), which has an independent operating system kernel and includes basic service components such as virtualized processors, memory, disks, and network bandwidth. The secure container combines the advantages of ordinary containers and virtual machines, and has good security isolation with the operating system kernel as the isolation granularity. A secure container can be regarded as a virtual machine and is usually directly deployed on a computing device.
[0047] A cluster refers to a group of computing devices that work together loosely or tightly, usually used to execute large jobs. Cluster-based computing devices usually have higher computing efficiency than single computing devices with comparable speed or availability. By parallel computing of multiple computing devices and using multiple computing resources to solve problems simultaneously, the computing speed and processing speed of the cluster system can be improved, and the overall performance of the cluster system can be enhanced. Each computing device in the cluster is interconnected through a network, and each computing device runs its own operating system.
[0048] Kubernetes (K8S) is an open-source container orchestration, scheduling, and management platform. By using K8S, the cumbersome manual operation steps of container orchestration can be eliminated, and the configuration, deployment, and scaling of containers become simple and efficient.
[0049] A cluster that uses K8S to manage containers can be called a K8S cluster. A K8S cluster can include several computing devices and virtual machines. A computing device or a virtual machine can be regarded as a node. K8S manages the containers running on each node in the K8S cluster with container groups (pods) as the smallest unit. A pod can encapsulate one or more containers.
[0050] Kubelet is a core functional component provided by K8S and can run on nodes such as computing devices and virtual machines. As an agent on the node, Kubelet is responsible for maintaining and managing tasks such as the creation, startup, and stop of the containers corresponding to the pods on each node, and communicating with K8S in real time to ensure the normal operation of the containers.
[0051] Currently, to ensure the security of containers, the first type of containers (such as secure containers) and the second type of containers (such as ordinary containers) are deployed on different computing nodes in the computing cluster, that is, only the first type of containers are deployed on a part of the computing nodes in the computing cluster, and only the second type of containers are deployed on another part of the computing nodes. In this way, the isolation between the first type of containers and the second type of containers is achieved through physical isolation, and the container scheduling is independent of each other and does not interfere with each other.
[0052] Figure 1 A schematic diagram of a container scheduling method provided by the prior art. As Figure 1 shown, ordinary containers are deployed based on virtual machines on a part of the computing nodes in the computing cluster, and secure containers are deployed on another part of the computing nodes. Physical isolation is achieved based on ordinary containers and secure containers, and these two different types of containers are scheduled separately, that is, the K8S ordinary container scheduler is responsible for the scheduling of ordinary containers, and the K8S secure container scheduler is responsible for the scheduling of secure containers. However, this separate scheduling method cannot meet the scenario of mixed deployment of ordinary containers and secure containers, resulting in inflexible container scheduling and low container scheduling efficiency.
[0053] To solve the problems of poor flexibility and low efficiency of container scheduling, this application provides a container scheduling method. This method is applied to a cloud management platform, which is used to manage a computing cluster that provides cloud services. This computing cluster includes multiple computing nodes. The method includes: first obtaining a request for indicating the deployment of different types of containers, and then determining the deployment location of this type of container according to the container type indicated by the request, and deploying the container indicated by the container type at the deployment location.
[0054] The container types requested here include at least one of the first container type or the second container type. Among them, the security isolation of the first type of containers indicated by the first container type is higher than that of the second type of containers indicated by the second container type. The deployment locations of the first type of containers and the second type of containers are on the same computing node, and the first type of containers are isolated from the second type of containers. Exemplarily, the first type of containers may include secure containers, and the second type of containers may include ordinary containers.
[0055] In this way, the scheduler uniformly schedules ordinary containers and secure containers. The ordinary containers and secure containers can be deployed on the same computing node of the computing cluster, ensuring that the cloud resources on the computing node can be fully utilized and improving resource utilization. Compared with the separate scheduling method of scheduling ordinary containers and secure containers separately, in this application, the scheduler uniformly and flexibly schedules ordinary containers and secure containers based on requests indicating the deployment of different types of containers, supports the scenario of hybrid deployment of ordinary containers and secure containers on the same computing node, makes container scheduling flexible, and improves the efficiency of container scheduling.
[0056] The application scenario of the scheduling method provided by this application, in addition to being applicable to the scenario of hybrid deployment of ordinary containers and secure containers on the same computing node, can also be applicable to the scenario of hybrid deployment of virtual machines and containers on the same computing node. Integrating different types of resources can reduce resource fragmentation, ensure that the cloud resources on the computing node can be fully utilized, and improve resource utilization.
[0057] The container scheduling method provided by this application will be introduced in detail below with reference to the accompanying drawings.
[0058] Figure 2 It is a schematic structural diagram of a data processing system provided by this application. As Figure 2 shown, the data processing system 200 includes a computing cluster 210 managed by a cloud platform and a scheduler 220.
[0059] Among them, the computing cluster 210 can provide cloud services for users based on a cloud resource pool. The cloud resource pool includes but is not limited to computing resources (such as virtual machine resources, container resources), storage resources, and network resources, etc. The computing cluster 210 that provides cloud services can be managed by the cloud platform so as to allocate cloud resources to users on demand according to resource usage requirements. The computing cluster 210 managed by the cloud platform is also the center for the data processing system 200 to process tasks. The computing nodes in the computing cluster 210 can use different types of containers to process tasks of different types of data.
[0060] The computing cluster 210 may include multiple computing nodes, such as Figure 2The computing nodes shown, such as computing node 211, computing node 212, and computing node 213. The first type of containers (such as secure containers) and the second type of containers (such as ordinary containers) can be mixed and deployed on any computing node in the computing cluster 210.
[0061] Here, Figure 2 computing node 211 in
[0062] is taken as an example. Kubelet can run on computing node 211, and Kubelet can create at least one secure container on computing node 221. At least one virtual machine can be deployed on computing node 211, such as the lightweight virtual machine MicroVM with good compatibility. Kubelet can also run on the virtual machine, and Kubelet can create at least one ordinary container on the virtual machine, that is, the ordinary container is deployed on computing node 211 in a nested virtual machine manner. In this way, different types of containers can be flexibly deployed on the computing node to meet the business requirements of different types of containers. The deployment of different types of containers makes full use of the cloud resources on the computing node and reduces resource waste.
[0063] The scheduler 220, as the coordination center of the data processing system 200, can be deployed in hardware form. For example, the scheduler 220 can be deployed on a separate computer device and connected to the computing nodes 211, 212, and 213 in the computing cluster 210 through a network. Another example is that the scheduler 220 can also be deployed on any computing node in the computing cluster 210. Optionally, the scheduler 220 can also run in software form in the cloud platform, and the scheduler 220 can be a K8S scheduler.
[0064] The scheduler 220 can be used to uniformly schedule different types of containers on any computing node in the computing cluster 210, control the execution of tasks such as container creation, startup, migration, stop, and deletion on the computing node, and monitor the running status of the container in real time. It can also be used to allocate different types of data processing tasks to the appropriate type of container. Through the coordination of the scheduler, the computing cluster 210 can respond to diverse data processing requirements in an efficient and flexible manner.
[0065] In this application, the scheduler 220 first obtains requests for instructing the deployment of different types of containers, and then determines the deployment locations in the computing cluster 210 where such types of containers can be deployed according to the container types indicated by the requests, and deploys the containers indicated by the container types at the deployment locations. The specific implementation method can refer to the content described in the subsequent steps 310 to 320.
[0066] Next, in conjunction with Figures 3 to 5 , the container scheduling method provided in this application will be described in detail. Figure 3 FIG. is a schematic flowchart of a container scheduling method provided in this application. Here, mainly taking Figure 2 as an example, the scheduler 220 deploys different types of containers on the same computing node according to the container types indicated by the requests. As Figure 3 shown, the container scheduling method may include the following steps.
[0067] Step 310: Obtain requests for container deployment.
[0068] The requests for container deployment can be used to indicate container types, and the container types can include at least one of a first container type or a second container type.
[0069] Among them, the security isolation of the first type of containers indicated by the first container type is higher than that of the second type of containers indicated by the second container type. The first type of containers here may include secure containers, and the second type of containers may include ordinary containers. Compared with ordinary containers, the main difference is that secure containers can be regarded as lightweight virtual machines, and each secure container has an independent operating system kernel, and the cloud resources used between different secure containers are isolated from each other. However, ordinary containers share the same operating system kernel and share cloud resources such as computing, storage, and network. Therefore, the security isolation of secure containers is higher than that of ordinary containers, that is, the security isolation of the first type of containers is higher than that of the second type of containers.
[0070] In some embodiments, the scheduler may receive requests for instructing the deployment of different types of containers sent by the cloud platform client. In this way, the scheduler obtains the requests for container deployment.
[0071] Optionally, the request may include a first identifier for indicating the first container type, and the first container type may be a secure container type. The request may further include a second identifier for indicating the second container type, and the second container type may be an ordinary container type.
[0072] The identifier can uniquely indicate the container type. Carrying the identifier in the request is beneficial for the scheduler to quickly identify the container type, so as to improve the efficiency of subsequent scheduling containers according to the container type.
[0073] Optionally, a request for deploying the first container type may be obtained first, and then a request for deploying the second container type may be obtained. Alternatively, a request for deploying the second container type may be obtained first, and then a request for deploying the first container type may be obtained. In the embodiments provided in this application, the order of obtaining the request indicating the deployment of the first container type and the request indicating the deployment of the second container type is not limited, nor is the number of requests indicating the deployment of any container type limited.
[0074] After the scheduler obtains requests for indicating the deployment of different types of containers, in response to the requests, according to the container type indicated by the requests, it determines the deployment location of the corresponding containers. The method for deploying the containers indicated by the container type at the container deployment location may refer to the content described in step 320 to step 330 below.
[0075] Step 320: Determine the container deployment location according to the container type indicated by the request.
[0076] As can be seen from the above step 310, the scheduler may obtain requests for indicating the deployment of the first container type or the second container type. The scheduler may, based on the different container types indicated by the requests, specifically determine the deployment location for this type of container.
[0077] After obtaining the request for indicating the deployment of the first container type, the scheduler may, according to the first container type indicated by the request, determine the container deployment location of the first type of container.
[0078] After obtaining the request for indicating the deployment of the second container type, the scheduler may, according to the second container type indicated by the request, determine the container deployment location of the second type of container.
[0079] Among them, the deployment location of the first type of container and the deployment location of the second type of container are on the same computing node of the computing cluster, so that the first type of container (such as a security container) and the second type of container (such as a normal container) can be mixed and deployed on the same computing node of the computing cluster to make full use of the cloud resources on the computing node, reduce the resource idle rate, and improve the resource utilization rate.
[0080] Step 330: Deploy the container indicated by the container type according to the container deployment location.
[0081] Although the physical locations where the first type of container (such as a security container) and the second type of container (such as a normal container) are deployed are the same, which may be the same computing node, the security container can be directly deployed on the computing node, while the normal container is deployed on the virtual machine of the computing node. Therefore, the deployment methods for deploying these two types of containers according to the container deployment location are different.
[0082] In some embodiments, the request may include the resource requirements of a container, and the resource requirements of the container may include computing resources (the number of CPUs measured in cores) required by the container, storage resources (the memory size measured in bytes), network resources (the amount of transmitted data measured in bandwidth), and so on.
[0083] The total amount of resources that the computing node where the container deployment location in the computing cluster is located can provide is limited, and the deployment of the container will occupy the resources of the computing node. When the remaining resources at the container deployment location meet the resource requirements of the container, the scheduler may deploy the container indicated by the container type. Based on the different container types, the deployment methods of secure containers and ordinary containers are introduced in step 331 and step 332 respectively below.
[0084] Step 331: When the remaining resources of the computing node meet the resource requirements, deploy the first type of container.
[0085] The amount of resources that each computing node in the computing cluster can provide is limited. Therefore, the resource requirements of the first type of container (such as a secure container) should be less than the remaining resources that the computing node can provide. Based on the fact that the secure container can be directly deployed on the computing node, the scheduler can select, from multiple computing nodes in the computing cluster, a computing node whose remaining resources can meet the resource requirements of the secure container as the deployment location of the secure container, and deploy the secure container at this deployment location.
[0086] It should be noted that if the resource sum of all secure containers in the container group becomes greater than or equal to the maximum resource supply of the computing node after the secure container to be deployed joins the secure container group of this computing node, the scheduler will not allocate this secure container to this computing node in order to reduce the occurrence of resource shortage during peak traffic usage periods.
[0087] The scheduler can uniformly manage the computing node and the virtual machines running on this computing node based on the functions provided by Kubelet. The secure container is directly deployed on the computing node, while the ordinary container is deployed on the virtual machine. To achieve the co-node deployment of different types of containers, the deployment location of the ordinary container should be on the computing node where the secure container is located, that is, the deployment location of the ordinary container is the same computing node in the computing cluster as the deployment location of the secure container in step 321 above. The deployment method of deploying the ordinary container on the virtual machine of this computing node is introduced in step 332 below.
[0088] Step 332: When the remaining resources of the first virtual machine of the computing node meet the resource requirements, deploy the second type of container on the first virtual machine.
[0089] The virtualized resources that each virtual machine in a computing node can provide are limited. Therefore, the resource requirements of the second type of containers (such as ordinary containers) should be less than the remaining resources of the virtual machine. Based on the fact that ordinary containers need to be deployed on the virtual machines of the computing node where the secure containers are located, the scheduler can select the first virtual machine whose remaining resources can meet the resource requirements of the ordinary containers from multiple virtual machines in the computing node as the deployment location of the ordinary containers, and deploy the ordinary containers at this deployment location.
[0090] In some embodiments, the scheduler can set a resource threshold as the "preheating water level" of the resources, and determine whether the remaining resources of the first virtual machine in the computing node are less than the resource threshold. The remaining resources here can be the resources that are completely idle on the first virtual machine without the occupation of resources because no ordinary containers are deployed yet, or the resources that are still available after some ordinary containers are deployed on the first virtual machine.
[0091] After the ordinary containers are deployed on the first virtual machine in the computing node, when the remaining resources of the first virtual machine are less than the resource threshold, the scheduler can create a second virtual machine on this computing node. When ordinary containers need to be deployed subsequently, they can be deployed on the created second virtual machine. The second virtual machine here can meet the required virtual machine specifications, and the virtual machine specifications can include basic virtualized components such as virtual processors, memory, disks, and network bandwidth.
[0092] Creating the second virtual machine can timely supplement the resources required for deploying ordinary containers, keeping the available resources above the "preheating water level" of the resources. Thus, idle available resources can be reserved in advance on the virtual machine. The advance preparation of resources is beneficial for the scheduler to quickly deploy ordinary containers on the virtual machine after receiving a request to deploy ordinary containers, improving the scheduling efficiency of ordinary containers. On the premise of ensuring that the resource capacity required for deploying ordinary containers is sufficient, reserving a certain amount of redundant resources can facilitate the rapid deployment of ordinary containers in the future.
[0093] In some other embodiments, when the deployment of ordinary containers has occupied all the resources on the first virtual machine in the computing node where the secure containers are located and the remaining resources of the first virtual machine in the computing node do not meet the resource requirements, the scheduler can create a second virtual machine on this computing node and deploy ordinary containers on the second virtual machine. The second virtual machine here can also meet the required virtual machine specifications, which will not be elaborated here.
[0094] As the number of deployed ordinary containers increases, it will lead to insufficient remaining resources of the virtual machines in the computing node, and the remaining resources may not be enough to continue deploying ordinary containers. When the remaining resources of the virtual machine do not meet the resource requirements, the scheduler can create virtual machines of the required specifications in real time on the computing node, so as to timely supplement the available resources, facilitate the rapid deployment of ordinary containers, and improve the scheduling efficiency of ordinary containers.
[0095] It should be noted that if the amount of resources currently available on the computing node is insufficient to support the creation of a second virtual machine with the required virtual machine specifications, the scheduler can select a computing node with sufficient resource supply in the computing cluster, create a second virtual machine on the computing node with sufficient resources, and deploy ordinary containers on the created second virtual machine.
[0096] To better understand the container scheduling method described in the above steps, the following introduces the process of the scheduler uniformly scheduling ordinary containers and secure containers on the same computing node with reference to the accompanying drawings. Figure 4 It is a schematic diagram of the process for uniformly scheduling ordinary containers and secure containers provided by this application. As Figure 4 shown, through the scheduling process determined by business and resource layering, the scheduler can first separate the ordinary container service requests and the secure container service requests, and then perform corresponding resource scheduling for different container types. The method executed by the scheduler includes the following specific steps:
[0097] Step 410: Obtain requests for indicating the deployment of different types of containers.
[0098] Step 420: Determine whether the request is for indicating the deployment of a secure container or for indicating the deployment of an ordinary container.
[0099] In the case of deploying a secure container, the following step 430 is executed.
[0100] In the case of deploying an ordinary container, the following steps 440 to 480 are executed.
[0101] Step 430: Select a computing node in the computing cluster whose remaining resources can meet the resource requirements of the secure container, and deploy the secure container on this computing node.
[0102] Step 440: Determine whether the remaining resources on the first virtual machine of the computing node where the secure container is located can meet the resource requirements of the ordinary container.
[0103] If the remaining resources on the first virtual machine of the computing node where the secure container is located meet the resource requirement conditions, the following steps 450 to 470 are executed.
[0104] If the remaining resources on the first virtual machine of the computing node where the secure container is located do not meet the resource requirement conditions, the following step 480 is executed.
[0105] Step 450: Deploy an ordinary container on the first virtual machine that meets the resource requirements of the ordinary container.
[0106] Step 460: Determine whether the remaining resources of the first virtual machine are less than the resource threshold.
[0107] Step 470: If the remaining resources of the first virtual machine are less than the resource threshold, then a second virtual machine with the required virtual machine specifications is created on the computing node where this secure container is located to supplement the available resources above the "preheating water level".
[0108] Otherwise, if the remaining resources of the first virtual machine are greater than or equal to the resource threshold, then the scheduling ends.
[0109] Step 480: A second virtual machine with the required virtual machine specifications is created on the computing node where the secure container is located, and ordinary containers are deployed on the virtual machine.
[0110] The container scheduling method provided by this application can be implemented based on the K8S container scheduling platform. The following introduces the method for unified scheduling of different types of containers on the same computing node based on the K8S platform in combination with the accompanying drawings. Figure 5 It is a schematic diagram of the process for unified scheduling of ordinary containers and secure containers based on K8S provided by this application, as Figure 5 shown:
[0111] (1) First, the Application Programming Interface Server (API Server) of K8S obtains the request for indicating the deployment of different types of containers, sends the request to the Unified Scheduler, and the Unified Scheduler processes the request.
[0112] (2) Next, the Unified Scheduler determines whether the request is for indicating the deployment of ordinary containers to meet the business requirements of ordinary containers; or for indicating the deployment of secure containers to meet the business requirements of secure containers.
[0113] (2.a) If the request is for indicating the deployment of secure containers, the Unified Scheduler allocates the request to the K8S Scheduler, as indicated by the dashed arrow in Figure 5 . The K8S Scheduler filters the computing nodes that meet the resource requirements of the secure containers from the computing cluster, and the Kubelet deploys the secure containers on this computing node.
[0114] (2.b) If the request is for indicating the deployment of ordinary containers, the Unified Scheduler allocates the request to the Preheating module, as indicated by the solid arrow in Figure 5 .
[0115] (3) Then, the Preheating module determines whether there are remaining resources on the first virtual machine of the computing node where the secure container is located that can meet the resource requirements of the ordinary containers.
[0116] (3.a) If there is no remaining resource on the first virtual machine, a second virtual machine is newly created on the computing node where the secure container is located. The warm-up module sends a request to the K8S scheduler and tags the second virtual machine to be created with the label "newly created". The K8S scheduler creates a second virtual machine on the computing node where the secure container is located according to the required specifications, and the Kubelet deploys ordinary containers on this newly created second virtual machine.
[0117] (3.b) If there are remaining resources on the first virtual machine, the warm-up module sends a request to the K8S scheduler and tags this first virtual machine with remaining resources with the label "warm-up". The K8S scheduler is responsible for the Kubelet to deploy ordinary containers on this first virtual machine.
[0118] (4) Finally, the warm-up module determines whether the remaining resources on the first virtual machine of the computing node where the secure container is located are less than the resource threshold, that is, whether the available resources are above the "preheating water level". Under the condition that the remaining resources are less than the resource threshold, the warm-up module sends a request to the K8S scheduler, and the K8S scheduler dynamically creates a second virtual machine on this computing node where the secure container is located according to the required specifications to supplement the available resources above the "preheating water level".
[0119] According to the container scheduling method provided in the above steps, the scheduler uniformly schedules ordinary containers and secure containers. The ordinary containers and secure containers can be deployed on the same computing node of the computing cluster, ensuring that the cloud resources on the computing node can be fully utilized and improving the resource utilization rate. Compared with the separate scheduling method of separately scheduling ordinary containers and secure containers, in this application, the scheduler uniformly and elastically schedules ordinary containers and secure containers based on requests indicating the deployment of different types of containers, supports the scenario where ordinary containers and secure containers are mixed and deployed on the same computing node, makes container scheduling flexible, and improves the efficiency of container scheduling.
[0120] The above mainly introduces the solution provided in the embodiments of this application from the perspective of the method. It can be understood that, in order to implement the above functions, the scheduler includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed in this article, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0121] In the above text, in combination with Figures 3 to 5 , it is described in detail the container scheduling method provided according to the embodiments of this application. Next, in combination withFigure 6 , describe the container scheduling device provided according to the embodiments of the present application.
[0122] Figure 6 It is a schematic structural diagram of a container scheduling device provided by the present application. These container scheduling devices can be used to implement the functions of the processor in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0123] As Figure 6 shown, the container scheduling device 600 includes an acquisition module 610, a scheduling module 620, and a deployment module 630.
[0124] The acquisition module 610 is used to acquire a request for container deployment. For example, the acquisition module 610 is used to execute Figure 3 step 310 in
[0125] The scheduling module 620 is used to determine the container deployment location according to the container type indicated by the request. The container type includes at least one of a first container type or a second container type. Among them, the security isolation of the first type of container indicated by the first container type is higher than that of the second type of container indicated by the second container type. The deployment location of the first type of container and the deployment location of the second type of container are on the same computing node, and the first type of container is isolated from the second type of container. For example, the scheduling module 620 is used to execute Figure 3 step 320 in
[0126] The deployment module 630 is used to deploy the container indicated by the container type according to the container deployment location. For example, the deployment module 630 is used to execute Figure 3 step 330 in
[0127] Optionally, when the deployment module 630 deploys the container indicated by the container type according to the container deployment location, it is specifically used to: deploy the first type of container on the computing node.
[0128] Optionally, when the deployment module 630 deploys the container indicated by the container type according to the container deployment location, it is specifically used to: deploy the second type of container on the virtual machine of the computing node.
[0129] Optionally, the request includes the resource requirements of the container; when the deployment module 630 deploys the container indicated by the container type according to the container deployment location, it is specifically used to: when the remaining resources at the container deployment location meet the resource requirements, deploy the container indicated by the container type.
[0130] Optionally, when the remaining resources at the container deployment location meet the resource requirements and the deployment module 630 deploys the container indicated by the container type, it is specifically used to: when the remaining resources of the first virtual machine on the computing node meet the resource requirements, deploy the second type of container on the first virtual machine. For example, the deployment module 630 is used to execute Figure 3Step 332 in
[0131] Optionally, after the second type of container is deployed in the first virtual machine, the above deployment module 630 is further specifically configured to: create a second virtual machine on the computing node when the remaining resources of the first virtual machine on the computing node are less than the resource threshold.
[0132] Optionally, the request includes the resource requirements of the container; when the deployment module 630 deploys the container indicated by the container type according to the container deployment location, it is specifically configured to: create a second virtual machine on the computing node when the remaining resources of the first virtual machine on the computing node do not meet the resource requirements; deploy the second type of container in the second virtual machine.
[0133] Optionally, when the remaining resources at the container deployment location meet the resource requirements and the deployment module 630 deploys the container indicated by the container type, it is specifically configured to: deploy the first type of container when the remaining resources of the computing node meet the resource requirements. For example, the deployment module 630 is used to execute Figure 3 Step 331 in
[0134] It should be understood that the container scheduling device 600 according to the embodiments of the present application may correspond to executing the methods described in the embodiments of the present application, and the above and other operations and / or functions of each unit in the container scheduling device 600 are for implementing Figure 3 the corresponding processes of the methods, and for the sake of brevity, they will not be described in detail here.
[0135] The container scheduling method provided by the embodiments of the present application can be applied to a computing device cluster, and the computing device cluster includes at least one computing device. Figure 7 This is a schematic structural diagram of a computing device provided by the present application. As Figure 7 shown, the computing device 700 includes a processor 710, a bus 720, a memory 730, a memory 750 (which can also be referred to as the main memory) and a communication interface 740. The processor 710, the memory 730, the memory 750 and the communication interface 740 are connected through the bus 720.
[0136] It should be understood that in this embodiment, the processor 710 may be a CPU, and the processor 710 may also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0137] The communication interface 740 is used to implement the communication between the computing device 700 and external devices or components. In this embodiment, the communication interface 740 is used to perform data interaction with other computing devices.
[0138] The bus 720 may include a path for transmitting information between the above components (such as the processor 710, the memory 750, and the storage 730). In addition to the data bus, the bus 720 may also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity, all kinds of buses are labeled as the bus 720 in the figure. The bus 720 may be a Peripheral Component Interconnect Express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), etc.
[0139] As an example, the computing device 700 may include multiple processors. The processor may be a multi-CPU processor. Here, the processor may refer to one or more devices, circuits, and / or computing units for processing data (such as computer program instructions). The processor 710 may first obtain a request for indicating the deployment of different types of containers (such as a request for indicating the deployment of a first container type or a request for indicating the deployment of a second container type), and then determine the deployment location of the containers of the type indicated by the request, and deploy the containers of the type indicated by the container type at the container deployment location.
[0140] It is worth noting that Figure 7 only the example where the computing device 700 includes 1 processor 710 and 1 storage 730 is taken here. Here, the processor 710 and the storage 730 are respectively used to indicate a type of device or equipment. In specific embodiments, the number of each type of device or equipment may be determined according to business requirements.
[0141] The memory 750 can correspond to storing the container deployment location, etc. in the above method embodiments. The memory 750 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0142] The memory 730 is used to store the container deployment location, etc., and can be a solid-state drive or a mechanical hard drive.
[0143] It should be understood that the computing device 700 according to this embodiment can correspond to the container scheduling device 600 in this embodiment, and the above and other operations and / or functions of each module of the container scheduling device 600 are respectively for implementing Figure 3 the corresponding processes in, and for the sake of brevity, will not be described herein again.
[0144] The method steps in this embodiment can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a computing device. Of course, the processor and the storage medium can also exist as discrete components in a network device or a terminal device.
[0145] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer or a laptop computer.
[0146] As Figure 8 shown, the computing device cluster includes at least one computing device 800. Instructions for executing the container scheduling method can be stored in the same manner in the memory 806 of one or more of the computing devices 800 in the computing device cluster. The functions of the bus 802, the processor 804, the memory 806, and the communication interface 808 can refer to the introduction of the corresponding content in Figure 7 and will not be elaborated here.
[0147] In some possible implementation manners, partial instructions for executing the container scheduling method can also be stored separately in the memory 806 of one or more of the computing devices 800 in the computing device cluster. In other words, a combination of one or more computing devices 800 can jointly execute the instructions for executing the container scheduling method.
[0148] It should be noted that the memories 806 in different computing devices 800 in the computing device cluster may store different instructions, which are respectively used to execute part of the functions of the container scheduling device. That is, the instructions stored in the memories 806 in different computing devices 800 can implement the functions of one or more of the acquisition module, the scheduling module, and the deployment module.
[0149] In some possible implementation manners, one or more computing devices in the computing device cluster may be connected through a network. Among them, the network may be a wide area network or a local area network, etc. Figure 9 A possible implementation manner is shown. As Figure 9 shown, two computing devices 900A and 900B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation manner, the memory 906 in the computing device 900A stores instructions for executing the functions of the acquisition module. At the same time, the memory 906 in the computing device 900B stores instructions for executing the functions of the deployment module. The functions of the bus 902, the processor 904, the memory 906, and the communication interface 908 can refer to Figure 7 the introduction of the corresponding content therein, which will not be elaborated here.
[0150] Figure 9 The connection manner between the computing device clusters shown can be considered that since the container scheduling method provided in this application needs to store a large amount of container deployment locations, it is considered to hand over the functions implemented by the acquisition module and the scheduling module to the computing device 900A for execution.
[0151] It should be understood that Figure 9 the functions of the computing device 900A shown in
[0152] This application embodiment also provides a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the container scheduling method.
[0153] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute the container scheduling method.
[0154] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid-state drive (SSD).
[0155] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A container scheduling method, characterized in that, The method is applied to a cloud platform for managing a computing cluster that provides cloud services. The computing cluster includes multiple computing nodes. The method includes: Obtaining a request for container deployment; Determining a container deployment location according to the container type indicated by the request. The container type includes at least one of a first container type or a second container type. Among them, the security isolation of the first type of container indicated by the first container type is higher than that of the second type of container indicated by the second container type. The deployment locations of the first type of container and the second type of container are on the same computing node, and the first type of container is isolated from the second type of container; Deploying the container indicated by the container type according to the container deployment location.
2. The method according to claim 1, wherein Deploying the container indicated by the container type according to the container deployment location includes: Deploying the first type of container on the computing node.
3. The method according to claim 1 or 2, characterized in that, Deploying the container indicated by the container type according to the container deployment location includes: Deploying the second type of container on a virtual machine of the computing node.
4. The method according to any one of claims 1 to 3, characterized in that The request includes the resource requirements of the container; deploying the container indicated by the container type according to the container deployment location includes: When the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type.
5. The method according to claim 4, wherein When the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type includes: When the remaining resources of the first virtual machine of the computing node meet the resource requirements, deploying the second type of container on the first virtual machine.
6. The method according to claim 5, characterized in that, After deploying the second type of container on the first virtual machine, the method further includes: When the remaining resources of the first virtual machine of the computing node are less than the resource threshold, creating a second virtual machine on the computing node.
7. The method according to any one of claims 1-3, characterized in that The request includes the resource requirements of the container; deploying the container indicated by the container type according to the container deployment location includes: When the remaining resources of the first virtual machine of the computing node do not meet the resource requirements, creating a second virtual machine on the computing node; Deploying the second type of container on the second virtual machine.
8. The method according to claim 4, characterized in that, When the remaining resources at the container deployment location meet the resource requirements, deploying the container indicated by the container type includes: When the remaining resources of the computing node meet the resource requirements, deploying the first type of container.
9. A container scheduling device, characterized in that, The device includes: An obtaining module for obtaining a request for container deployment; A scheduling module for determining a container deployment location according to the container type indicated by the request. The container type includes at least one of a first container type or a second container type. Among them, the security isolation of the first type of container indicated by the first container type is higher than that of the second type of container indicated by the second container type. The deployment locations of the first type of container and the second type of container are on the same computing node, and the first type of container is isolated from the second type of container; A deployment module for deploying the container indicated by the container type according to the container deployment location.
10. A scheduler, characterized in that, The scheduler includes a memory and a processor, and the memory is used for storing a set of computer instructions; when the processor executes the set of computer instructions, the operation steps of the method described in any one of claims 1-8 above are performed.
11. A data processing system, characterized in that, The data processing system includes a computing cluster and a scheduler, the computing cluster is used for providing cloud services, the computing cluster includes a plurality of computing nodes, the scheduler includes a memory and a processor, and the memory is used for storing a set of computer instructions; when the processor executes the set of computer instructions, the operation steps of the method described in any one of claims 1-8 above are performed.
12. A computer-readable storage medium, characterized in that, It includes computer program instructions, and when the computer program instructions are executed by the scheduler, the scheduler performs the operation steps of the method described in any one of claims 1-8.
13. A computer program product comprising instructions, characterized in that, When the instructions are executed by the scheduler, the scheduler performs the operation steps of the method described in any one of claims 1-8.