Service management and reasoning service methods, devices, storage media, and program products
By parsing the privacy information of the target service to generate a configuration requirement file, and dynamically managing container groups and virtual machines, the problem of applications in the container escaping to the kernel is solved, and the security and reliability of service management are improved.
Patent Information
- Application Number
- CN202510927615.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-07
AI Technical Summary
Applications within containers can easily escape to the kernel, causing data crosstalk that impacts data reliability and makes service management with high privacy requirements unreliable, posing exposure risks.
By obtaining the configuration request of the target service, parsing the privacy information to form a configuration requirement file, using the container monitoring process to control the scheduler to select the appropriate computing node to create a container group, and initialize the virtual machine to run the target container, dynamically generating a configuration requirement file that adapts to the target service to build the service environment.
It improves the security and reliability of service management, adapts to the dynamic management of various services, and reduces the risk of data leakage.
Smart Images

Figure CN120434119B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud service technology, and in particular to a service management method, an inference service method, an electronic device, a computer-readable storage medium, and a computer program product. Background Art
[0002] To address the issue of containerized applications easily escaping to the kernel, a separate virtual machine is typically deployed for each container, allowing the container to operate independently from the kernel. However, even with this approach, data crosstalk can still affect data reliability. Furthermore, even applications with high privacy requirements can still be exposed, leading to unreliable service management. Summary of the Invention
[0003] The present application provides a service management method, an inference service method, an electronic device, a computer-readable storage medium, and a computer program product to at least solve the problem of unreliable service management in related technologies.
[0004] The present application provides a service management method, which includes: obtaining a configuration request for a target service; parsing privacy information carried in the configuration request to form a configuration requirement file, and mounting the configuration requirement file to a container monitoring process; in response to obtaining a creation request for the target service, obtaining the configuration requirement file from the container monitoring process, controlling a scheduler to select a computing node that is compatible with the configuration requirement file to create a container to form a running container group; wherein the running container group includes at least one target container running the target service; initializing a new virtual machine as a target virtual machine, and controlling the target virtual machine to run a target container to run the target service in the target container.
[0005] The present application also provides an inference service method, which includes: using the above-mentioned service management method to manage the target inference service; obtaining the data to be inferred; and inputting the data to be inferred into the target inference service to obtain the inference output of the target inference service.
[0006] The present application also provides an electronic device, which includes: a memory and a processor; the memory is used to store computer programs; the processor is used to implement the steps of the above-mentioned service management method when executing the computer program; or, implement the steps of the above-mentioned reasoning service method.
[0007] The present application also provides a computer-readable storage medium, in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of the service management method described above are implemented; or, the steps of the reasoning service method described above are implemented.
[0008] The present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the above-mentioned service management method; or, it implements the steps of the above-mentioned reasoning service method.
[0009] This application allows for the preconfiguration of privacy information for a target service in a configuration request, and uses this privacy information to indicate the privacy and / or importance of the target service. This allows for a dynamic generation of a configuration requirements file tailored to the target service based on the privacy information in the configuration request before the target service is created. When the target service is created, the corresponding service environment can be built based on the configuration requirements file to accommodate the required privacy level of the target service. This resolves the technical issue of unreliable service management and achieves the technical effect of adapting the dynamic management of each service to improve service management security and service operation reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0011] Figure 1 This is a schematic diagram of an embodiment of an application scenario of the service management method of this application;
[0012] Figure 2 This is a flowchart of an embodiment of the application service management method;
[0013] Figure 3 This is a flowchart of another embodiment of the application service management method;
[0014] Figure 4 A flowchart illustrating an embodiment of forming a configuration requirement document for this application;
[0015] Figure 5 This is a flowchart of an embodiment of running a target container according to the present application;
[0016] Figure 6 This is a flow chart of an embodiment of monitoring a running container according to the present application;
[0017] Figure 7 This is a flowchart of an embodiment of security authority management for this application;
[0018] Figure 8 This is a flowchart of an embodiment of the working principle of the service management model of this application;
[0019] Figure 9This is a flowchart of an embodiment of the reasoning service method of this application. DETAILED DESCRIPTION
[0020] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0021] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.
[0022] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0023] In conjunction with the specific application environment architecture or specific hardware architecture on which the execution of the service management method and the reasoning service method depends, the specific application environment architecture or specific hardware architecture is described herein.
[0024] See also Figure 1 , Figure 1 This is a scenario diagram of an embodiment of an application scenario of the service management method of this application.
[0025] In one embodiment, the application scenario of the service management method may generally include a service management device 10 and a computing cluster 20. The service management device 10 is connected to the computing cluster 20.
[0026] The service management device 10 is used to implement the service management method. In this embodiment, the service management can at least participate in service creation. In addition, the service management device 10 can also participate in at least one service management such as creation, update, suspension, and termination.
[0027] The service management device 10 may have interfaces, modules, units, etc. for interacting with the outside world to receive requests for service configuration and service creation. The requested service may be used as the target service, and the configuration requirements of the target service may be parsed. The target service may then be deployed on the computing cluster 20 according to the parsed configuration requirements.
[0028] Optionally, the service management device 10 may be connected to one or more computing clusters 20 to serve the service management of the computing clusters 20 to which it is connected. Figure 1 , which illustrates an application scenario in which the service management device 10 can be connected to multiple computing clusters 20 .
[0029] The computing cluster 20 can be considered as a system consisting of multiple interconnected computers, each of which can be considered as a computing node. For example, the computing node can be a server, etc. The computing node can include a processor that can support operations. For example, the processor type can include at least one of a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and an accelerator card (i.e., an accelerated processor). That is, when the processor type includes a CPU, a GPU, and an accelerated processor, the service startup method of the present application can be compatible with the processor deployment details of the inference service on the aforementioned processor types, thereby improving the functionality of service startup management and further improving the startup efficiency of the inference service.
[0030] The embodiments of the present application provide a service management method. The service management principle of the service management method is described in detail below in conjunction with the execution process of the service management method.
[0031] See also Figure 2 , Figure 2 This is a flowchart of an embodiment of the service management method of this application.
[0032] S101: Obtain a configuration request for a target service.
[0033] In this embodiment, the target service represents the service currently being configured. The configuration request is a request for adaptive configuration of the target service.
[0034] Configuration requests can carry the target service's privacy level information. This privacy level information indicates the target service's desired privacy and / or importance level for its data. This information can be used to determine the target service's required privacy level based on the configuration request before creating the service, thereby facilitating adaptation to the target service's actual privacy requirements.
[0035] S102: Parse the privacy information carried in the configuration request to form a configuration requirement file, and mount the configuration requirement file to the container monitoring process.
[0036] In this embodiment, in response to obtaining a configuration request, the privacy information carried in the configuration request can be identified and parsed, so as to obtain the privacy requirements of the target service and adaptively form a configuration requirement file, and mount the configuration requirement file to the container monitoring process.
[0037] A configuration rule library can be pre-established. When creating a configuration requirements document, configuration rules associated with the privacy level information can be extracted from the configuration rule library and integrated to form the configuration requirements document. Alternatively, the privacy level information can include configuration rules for target service requirements, and the configuration requirements document can be generated by converting the privacy level information.
[0038] S103: In response to obtaining a creation request for a target service, obtaining a configuration requirement file from the container monitoring process, and controlling the scheduler to select a computing node that is compatible with the configuration requirement file to create a container to form a running container group; wherein the running container group includes at least one target container running the target service.
[0039] In this embodiment, the creation request is used to request the creation of a target service. The computing cluster may include one or more computing nodes. The computing cluster or the service management device may also include a scheduler. The scheduler is used to select a computing node from the computing cluster to run the target service.
[0040] In response to forming a configuration requirement file of the target service and obtaining a creation request of the target service, a pre-mounted configuration requirement file can be obtained from the container monitoring process to build a service operating environment for the target service according to the configuration requirement file.
[0041] The scheduler can be controlled to select compute nodes that match the configuration requirements file for container creation. Specifically, the scheduler can identify the configuration requirements file to obtain the privacy and operating environment requirements of the compute nodes, select compute nodes from the compute cluster that meet the privacy and operating environment requirements of the target service, create one or more containers for running the target service on the selected compute nodes as target containers, and use the created one or more target containers as the running container group for running the target service.
[0042] S104: Initialize a new virtual machine as a target virtual machine, control the target virtual machine to run a target container, and run a target service in the target container.
[0043] In this embodiment, a virtual machine can be created in the computing cluster and / or an idle virtual machine can be initialized to form a new virtual machine as the target virtual machine. In response to the completion of the formation of the target virtual machine, the target virtual machine can be controlled to run the target container to start the target container and enable the target container to run the target service, thereby realizing the service task of the target service.
[0044] As can be seen, since the privacy level information of the target service can be configured in advance in the configuration request, the privacy level information can be used to indicate the privacy and / or importance of the target service. In this way, before the target service is created, a configuration requirement file suitable for the target service can be dynamically generated based on the privacy level information in the configuration request. When the target service is created, the corresponding service environment can be built according to the configuration requirement file to adapt to the privacy level required by the target service, thereby adapting to the dynamic management of each service, which can further improve the security of service management and the reliability of service operation.
[0045] See also Figure 3 , Figure 3 This is a flowchart of another embodiment of the service management method of this application.
[0046] S201: Obtain a service creation form.
[0047] In this embodiment, the configuration request can be embodied in a form, i.e., a service creation form. In an alternative embodiment, the configuration request can also be in other data forms, which are not limited here.
[0048] S202: Evaluate the service attributes of the target service as privacy information.
[0049] In this embodiment, when forming a service creation form, a privacy level field may be preset in the annotation field (such as annotations) of the target service, wherein the attribute value of the preset privacy level field may be used as the privacy level information.
[0050] If so, in response to obtaining the service creation form, the preset privacy level field of the service metadata when deploying the target service can be identified to use the service attribute represented by its attribute value as the privacy level information.
[0051] Furthermore, the privacy level information may include priority requirement information and / or privacy requirement information. Specifically, the privacy level information may include priority requirement information; the privacy level information may include privacy requirement information; and the privacy level information may include priority requirement information and privacy requirement information.
[0052] Priority requirement information can be reflected in a priority field (such as the importance field) to indicate the importance of the target service. For example, the priority field can be used to identify the priority of allocable storage resources and resource compensation policies.
[0053] Privacy requirement information can be reflected in a privacy field (such as the sensitivity field) to indicate the data sensitivity of the target service. For example, the data isolation level of the target service can be identified based on the privacy field.
[0054] S203: Form a demand profile that matches the privacy level information.
[0055] In this embodiment, the service management device may include a control module, wherein the control module may include a service attribute evaluation unit.
[0056] After obtaining the service creation form, the control module (service attribute evaluation unit) verifies whether the target service's privacy information, mounted volumes, CPU, memory storage, and other parameters meet the requirements. If the verification passes, the creation operation is allowed and submitted to container management applications such as Kubernetes for processing, forming a demand profile that matches the privacy information.
[0057] Among them, Kubernetes is an open source application software with container management functions.
[0058] S204: Perform policy execution processing on the demand configuration file.
[0059] In this embodiment, in response to forming a requirement configuration file, the requirement file may be configured to be mounted to the container monitoring process.
[0060] S205: Create a target service according to the requirement configuration file.
[0061] In this embodiment, in response to forming a configuration requirement file and obtaining a creation request for a target service, the configuration requirement file can be obtained from the container monitoring process, and the control scheduler selects a computing node that is compatible with the configuration requirement file to create a container to form a running container group.
[0062] That is, the scheduler can be controlled to select an appropriate computing node to create a running container group. Specifically, after receiving the instruction to create a running container group, the node agent component (such as kubelet) on the computing node can call an interface such as the environment provision component to initialize a new virtual machine (VM) to run the container, namely the target virtual machine. Specifically, when running the target service through the target container, it is usually necessary to configure the environment provision component. Among them, the environment provision component is used to provide an independent operating environment for each container. For example, Kata Containers can be used. Kata Containers is an open source container runtime project. In this embodiment, Kata Containers can be customized to form an environment provision component that is suitable for the service management method of this embodiment.
[0063] The kubelet acts as a node agent, managing the running container groups assigned to compute nodes. These groups are represented by pods, which represent container encapsulation and can consist of one or more containers. These pods provide an environment for collaborative work between containers, allowing them to share resources such as networking, storage, and lifecycle management.
[0064] Specifically, in combination with step S205 and step S206, when a container creation request is received through the CRI (Container Runtime Interface), the container function management component (such as containerd, etc.) can call its built-in container monitoring process (such as the Kata Runtime plug-in, i.e., Kata Shim's containerd-shim-kata-v2, etc.). The container monitoring process can parse OCI (Open Container Initiative) specifications such as container configuration and root file system to obtain the configuration requirement file of the target service.
[0065] For example, if the first level of the requirement configuration file is the file keyword, the file keyword represents file-related permissions. Suppose the permission content is " / etc / passwd---", which first contains the directory or file information, and then the type of allowed operation. "---" means that reading, writing, and execution are not allowed. That is, the meaning of this configuration is that reading, writing, and execution operations are not allowed on the system directory / etc / passwd.
[0066] S206: Monitor the target service.
[0067] In this embodiment, in response to achieving the creation of the target service, the operating status of the target service may also be monitored. The monitoring scope may include security anomaly event monitoring and / or resource overload event monitoring. That is, the monitoring scope may include security anomaly event monitoring; the monitoring scope may include resource overload event monitoring; the monitoring scope may include security anomaly event monitoring and resource overload event monitoring. This embodiment will be described later using the example that the monitoring scope may include security anomaly event monitoring and resource overload event monitoring.
[0068] S207: Determine whether a security anomaly occurs.
[0069] In this embodiment, when a security anomaly occurs, step S208 is executed. When no security anomaly occurs, step S211 is executed.
[0070] S208: Update the security permission level and load it into the configuration requirement file to update the configuration requirement file, and execute the new configuration file to update the abnormal container.
[0071] In this embodiment, in response to the occurrence of a security anomaly event, the target service can update the security permission level operation, and the updated security permission level can be reloaded into the configuration requirement file to update the configuration requirement file, and the new configuration file can be executed to update the anomaly container to reduce the risk of the security anomaly event affecting the execution reliability of the target service.
[0072] S209: Determine whether a resource overload event occurs.
[0073] In this embodiment, when a resource overload event occurs, step S210 is executed. When no resource overload event occurs, step S211 is executed.
[0074] S210: Perform amplification processing on the observation resources.
[0075] S211: Keep running the target service.
[0076] In this embodiment, in response to no abnormal security event and no resource overload event occurring, the current running state of the target service can be maintained. Furthermore, step S206 can be continued to continuously monitor the target service.
[0077] The following is an example of the detailed principle of forming a configuration file in this embodiment. Figure 4 , Figure 4 A flowchart illustrating an embodiment of forming a configuration requirement file for this application.
[0078] S301: Obtain a configuration request for a target service.
[0079] S302: Parse the configuration request.
[0080] In this embodiment, the service metadata of the deployment target service carried in the configuration request may be parsed.
[0081] S303: Determine whether the privacy level information is parsed.
[0082] In this embodiment, when the privacy level information is parsed, step S304 is executed. When the privacy level information is not parsed, step S305 is executed.
[0083] Specifically, it is possible to identify whether the service metadata carries privacy information. For example, it is possible to identify whether a priority field and a privacy field are preset in the code annotation.
[0084] S304: Extracting privacy information.
[0085] In this embodiment, the code annotation of the target service carried in the configuration request is obtained. The priority field and the privacy field preset in the code annotation are identified. The attribute value of the priority field is extracted as a priority factor, and the attribute value of the privacy field is extracted as a privacy factor. The priority factor and the privacy factor are used as privacy information. This embodiment can thus improve the information richness of the annotation information in the service metadata and reduce the number of additional files to be obtained, thereby improving service management efficiency and, in turn, enhancing service reliability and security.
[0086] S305: Using the default level information as the privacy level information.
[0087] In this embodiment, the default privacy level information may be a relatively low level of privacy, so as to reduce the risk of assigning too high a privacy level to the target service and crowding out high-level service resources.
[0088] S306: Forming a privacy configuration strategy that matches the privacy factor in the privacy level information.
[0089] In this embodiment, the privacy factor is used to represent the degree of privacy required when the target service is running.
[0090] A privacy factor included in the privacy level information may be obtained to form a privacy configuration policy that matches the privacy factor. The privacy configuration policy includes providing a physical processor matching the privacy factor to the target service in response to a target service requesting a physical processor resource, so that the target service can utilize the physical processor resource.
[0091] For example, in this embodiment, the privacy factor can be preset to a two-level privacy level. This can reduce the burden of multiple levels of identification and differentiated configuration through reasonable privacy level settings, and can also facilitate reasonable resource planning. Specifically, the two-level privacy level can include a first privacy expectation and a second privacy expectation.
[0092] The first privacy expectation has a higher privacy requirement than the second privacy expectation. In addition, both the first privacy expectation and the second privacy expectation can be represented by numerical values, text, fields, etc., which are not limited here.
[0093] Specifically, combined with the configuration process of the target service in this embodiment, the privacy factor in the privacy level information can be obtained and identified.
[0094] When the privacy factor meets the first privacy expectation, a number of physical processors required by the target service is provided as the first processor, and the first processor is controlled to be isolated from other services.
[0095] When the privacy factor meets the second privacy expectation, the fine-grained number of physical processors matched with the resources requested by the target service is evaluated, the fine-grained number of physical processors is provided as the second processor, and the second processor is controlled to be shareable with other services.
[0096] In layman's terms, when a target service whose privacy factor meets the first privacy expectation requires a physical processor such as a heterogeneous accelerator card, heterogeneous card isolation can be provided to allocate a whole card to the target service, effectively reducing data leakage caused by sharing physical processors with other services. In other words, when requesting resources, the target service is only allowed to use an integer number of accelerator cards, allowing the target service to exclusively use the accelerator card resources, thereby preventing data leakage. Heterogeneous accelerator cards can be GPUs (Graphic Processing Units), MLUs (a type of accelerator card), etc., and are not limited here.
[0097] When a target service with a privacy factor that meets the second privacy expectation requires heterogeneous physical processors such as accelerator cards, fine-grained allocation can be used. Fine-grained allocation allows multiple services to share a single accelerator card. Using a custom fine-grained service scheduler, you can allocate a portion of the accelerator cards when creating the target service, for example, allocating 0.1 accelerator cards, thereby improving physical processor resource utilization.
[0098] Furthermore, in response to obtaining service data of the target service, the service data is encrypted and stored using an encryption component, network access rules and file access rules are configured as constraint rules, and the target container is controlled to comply with the constraint rules when running the target service as a first security configuration. The second security configuration corresponding to the second privacy expectation has a lower degree of constraint than the first security configuration.
[0099] Specifically, let's take the Key Management Service (KMS) as an example. A master key can be created in KMS. The "create-datakey" interface of KMS can be called to create a data encryption key. This creates a plaintext data encryption key and a ciphertext data encryption key. The ciphertext data encryption key is generated by encrypting the plaintext data encryption key with the master key. The plaintext data encryption key can be used to encrypt a plaintext file to generate a ciphertext file. The ciphertext data encryption key and the ciphertext file are stored together in a persistent storage device or service.
[0100] Accordingly, when decrypting data, the ciphertext data encryption key and ciphertext file can be read from the persistent storage device or service. Users call the KMS "decrypt-datakey" API and use the corresponding master key to decrypt the ciphertext data encryption key and obtain the plaintext data encryption key. The master key is the same key used to generate the ciphertext data encryption key. Accidentally deleting the corresponding master key will cause decryption failure. Therefore, proper management of master keys is essential. Ciphertext files can be decrypted using the plaintext data encryption key.
[0101] S307: Forming a priority configuration strategy that matches the priority factor in the privacy level information.
[0102] In this embodiment, a priority factor included in the privacy information is obtained; wherein the priority factor is used to characterize the resource priority of the target service operation; a priority configuration strategy matching the priority factor is formed; wherein the priority configuration strategy includes: in response to the current resources of the computing cluster where the target service is deployed being lower than the resource threshold, applying a resource scheduling mode matching the priority factor to the target service.
[0103] For example, in this embodiment, the priority factor can be preset to a two-level priority / importance. This can reduce the burden of excessive level identification and differentiated configuration through reasonable priority stage settings, and can also facilitate reasonable resource planning. That is, the two-level priority can include a first priority expectation, a second priority expectation, and a third priority expectation.
[0104] The resource priorities of the first priority expectation, the second priority expectation and the third priority expectation are sequentially reduced. Moreover, the first priority expectation, the second priority expectation and the third priority expectation can be represented by numerical values, text, fields, etc., which are not limited here.
[0105] Specifically, when the priority factor meets the first priority expectation, other services with other priority expectations are selected as the first service, and the service process of the first service is suspended so that the target service can obtain the operating resources of the first service, thereby prioritizing the guarantee that the target service whose priority factor meets the first priority expectation has sufficient available resources, which is conducive to ensuring the operating stability of the target service, and thus can improve the security and reliability of the target service.
[0106] When the priority factor meets the second priority expectation, the second service is selected and its service process is suspended to allow the target service to obtain the operating resources of the second service. The second service indicates that its priority expectation represents a lower resource priority than other services in the second priority expectation, to ensure the operational stability of the target service with higher resource priority.
[0107] When the priority factor meets the third priority expectation, the control target service does not obtain the running resources of other services.
[0108] For example, when a user creates a service, the importance and sensitivity mentioned in the present invention need to be set. If not set, the default sensitivity is sensitive and low importance, and the lowest level of security policy is implemented. The service attribute evaluation module detects the service metadata submitted by the user, obtains the annotation data, and parses the attribute values of the importance field and the sensitivity field in the annotation, such as importance: high and sensitivity: confidential. According to predefined rules, the importance is scored from low to high as 1 point, 2 points, and 3 points respectively. The higher the score, the more important it is. Different scores will match different resource allocation and preemption strategies, and the sensitivity parameters sensitive (sensitive) and confidential (secret) keywords will match the corresponding isolation strategy, among which the confidential isolation strategy is stronger. Thus, the model importance score (1-3) and sensitivity classification (sensitive / secret) are generated to prepare for the subsequent execution of different strategies.
[0109] S308: The private configuration policy and the priority configuration policy are mounted as configuration requirement files to the container monitoring process for creating a target service.
[0110] For example, the attribute value corresponding to the first privacy expectation can be "sensitive", and the attribute value corresponding to the second privacy expectation can be "confidential". The attribute value corresponding to the first priority expectation can be "high", the attribute value corresponding to the second priority expectation can be "medium", and the attribute value corresponding to the third priority expectation can be "low". In this embodiment, the annotation data can be parsed to obtain the attribute values of the importance field and sensitivity field in the annotation. For example, privacy level information includes: importance: high, sensitivity: confidential.
[0111] Based on predefined rules, priority factors can be scored as 1, 2, or 3 points, with higher scores indicating a higher priority for reliable operation. Different scores can be matched to different resource allocation and compensation strategies. The sensitive and confidential keywords in the privacy factor parameters can be matched to corresponding isolation strategies, preparing for the subsequent execution of different strategies.
[0112] Furthermore, corresponding factor scores can be assigned to the priority factor and the privacy factor respectively. The service type of the target service is obtained, and the dimension tendency that the service type characterizes the target service tends to be as the target tendency; wherein, the dimension tendency includes the priority tendency and the privacy tendency. The factor scores of the priority factor and the privacy factor are weighted and fused to obtain the target service score, and the weight of the target tendency is controlled to be higher than the weights of other tendencies. Determine whether the target service score reaches the scoring threshold. In response to the target service score reaching the scoring threshold, the privacy factor of the target service is updated to meet the first privacy expectation, and the priority factor of the target service is updated to meet the first priority expectation. In this way, the overall importance of the target service can be quantified, and the security authority level policy of the target service with significantly high importance after quantification can be upgraded, so as to ensure the operational reliability of the target service with significantly high importance.
[0113] The following is an example of the configuration code for the privacy factor that meets the first privacy expectation:
[0114] “# File system access control
[0115] file:
[0116] / etc / passwd ---, # Prohibit modification of system key files
[0117] / proc / * / mem ---, # prohibit access to other process memory
[0118] / var / lib / docker / containers / ** r, # Allow reading of the container's own configuration file
[0119] # Network access restrictions
[0120] network:
[0121] deny network raw, # prohibit raw sockets
[0122] network inet tcp,udp, # Only allow TCP protocol".
[0123] The following is an example of the configuration code for a privacy factor that meets the second privacy expectation:
[0124] “file:
[0125] / var / lib / app / data / ** rw, # Only allow access to the specified data directory
[0126] / ** r--, # prohibit writing to all other paths
[0127] network:
[0128] network inet tcp ,# Only allow TCP protocol".
[0129] The above can form a private configuration policy, which can be mounted to the service through configmap and named "safetypolicy". Configmap is a core resource object used to store configuration data. It stores configuration information through key-value pairs or files, achieving decoupling of application configuration and container images.
[0130] See also Figure 5 , Figure 5 This is a flowchart of an embodiment of running a target container according to the present application.
[0131] S401: Obtain a creation request for a target service.
[0132] S402: Obtain a configuration requirement file from the container monitoring process.
[0133] S403: Control the scheduler to select a computing node that is compatible with the configuration requirement file.
[0134] S404: Create a container on the adapted computing node to form a running container group including the target container.
[0135] S405: Initialize a new virtual machine as a target virtual machine, and control the target virtual machine to run the target container.
[0136] In this embodiment, a new virtual machine is initialized as a target virtual machine, and the target virtual machine is controlled to run a target container, so as to run a target service in the target container.
[0137] Specifically, the target virtual machine is triggered to start up, and the configuration requirement file is delivered to the hosting component of the target virtual machine, so that the hosting component recognizes the configuration requirement file and forms a target virtual interface.
[0138] Controls the startup of the managed component process, loads the kernel, and initializes the virtual machine environment to load the target virtual machine into the kernel.
[0139] The target container includes a management component of an agent program, and the container monitoring process establishes a remote connection with the management component through the socket interface of the computing node to which it belongs, so as to build a communication link between the inside and outside of the target container.
[0140] For example, the target virtual interface may include a first virtual interface and / or a second virtual interface.
[0141] Specifically, a first virtual interface can be constructed as a target virtual interface, file data can be sent to the first virtual interface, the first virtual interface can be instructed to parse permission configuration statements in the configuration requirement file, convert the permission configuration statements into permission statement codes using a counting method, and call a system management interface to identify the permission statement codes to perform permission configuration on the file data.
[0142] Construct a second virtual interface as the target virtual interface. Obtain network filtering rules from the configuration requirements file. Initialize the network filtering function of the second virtual interface. Configure the network filtering function to allow traffic from the local loopback interface and the first protocol, and deny traffic from the second protocol and unknown network protocols. The first protocol is the network protocol identified by the network filtering rule as receiving data, and the second protocol is the network protocol identified by the network filtering rule as rejecting data.
[0143] The following provides examples of the detailed process of creating the first virtual interface and the second virtual interface in combination with specific existing components, systems, etc.
[0144] After parsing the policy configuration, the Kata Shim (hosting component) calls the Kata Runtime. Based on the configuration, the Kata Runtime generates a QEMU (processor emulation software) startup command to trigger the VM startup and pass the policy configuration to QEMU. QEMU can add two interfaces: one for file permissions (the first virtual interface) and one for network-related logic (the second virtual interface). The QEMU process starts, loads the kernel, and initializes the target VM environment. After the kernel is loaded within the target VM, the Kata Agent (management component) starts. The Shim establishes a gRPC connection with the Agent within the target VM via the VSOCK interface (socket interface, such as / dev / vhost-vsock) on the compute node host, enabling communication within and outside the container. gRPC is a remote procedure call framework.
[0145] The first virtual interface can pass in the relevant files or folders and the permission configuration in the policy, such as "rwx". By mapping the permission configuration statement to the corresponding octal code, the system interface can be called to modify the permissions of the files and folders. The specific relevant code can be as follows:
[0146] " / / Modify file permissions
[0147] func filePermission(folder string, op string) error {
[0148] var perm os.FileMode
[0149] if perm == "rwx" {
[0150] / / Set read, write and execute permissions
[0151] perm = 0777
[0152] }else if perm == "rw" {
[0153] perm = 0666
[0154] }……
[0155] err := os.Chmod(folder, perm)
[0156] if err != nil {
[0157] return fmt.Errorf("Failed to modify %s permissions: %w", folder, err)
[0158] }
[0159] return nil
[0160] }".
[0161] The second virtual interface is for security considerations in network configuration. For example, the TCP (Transmission Control Protocol) protocol has various security risks, such as TCP SYN, or flooding attack, which uses the TCP three-way handshake mechanism to consume server resources and has the risk of causing service downtime. In addition, TCP Land attack (local area network denial of service attack) also causes system crashes by sending data packets with the same source IP (Internet Protocol) and target IP. Some services can choose to disable TCP to reduce the relevant attack surface. Therefore, a corresponding network configuration module can be provided in this embodiment, so that users can customize network policies to maintain the security of services, such as enabling or disabling certain network protocol traffic, rejecting all traffic that is not explicitly allowed, etc. The specific relevant code can be as follows:
[0162] " / / Network settings
[0163] / / SetNetworkProtocol sets the network protocol rules according to the passed deny flag and protocol name
[0164] func SetNetworkProtocol(deny bool, protocol string) error {
[0165] / / Clear all existing iptables rules
[0166] err := clearIPTablesRules()
[0167] if err != nil {
[0168] return fmt.Errorf("Failed to clear iptables rules: %w", err)
[0169] }
[0170] / / Allow all traffic on the local loopback interface
[0171] err = allowLoopbackTraffic()
[0172] if err != nil {
[0173] return fmt.Errorf("Failed to allow local loopback traffic: %w", err)
[0174] }
[0175] if deny {
[0176] / / If deny is true, deny traffic of the specified protocol
[0177] err = denyProtocol(protocol)
[0178] if err != nil {
[0179] return fmt.Errorf("Reject %s protocol failed: %w", protocol, err)
[0180] }
[0181] } else {
[0182] / / If deny is false, allow traffic of the specified protocol
[0183] err = allowProtocol(protocol)
[0184] if err != nil {
[0185] return fmt.Errorf("Failed to allow %s protocol: %w", protocol, err)
[0186] }
[0187] }
[0188] / / Deny all traffic not explicitly allowed
[0189] err = denyAllOtherTraffic()
[0190] if err != nil {
[0191] return fmt.Errorf("Failed to reject other traffic: %w", err)
[0192] }
[0193] return nil
[0194] }
[0195] / / clearIPTablesRules clears all existing iptables rules
[0196] func clearIPTablesRules() error {
[0197] _, err := systemcmd.Execute("iptables -F")
[0198] if err != nil {
[0199] return err
[0200] }
[0201] _, err = systemcmd.Execute("iptables -X")
[0202] if err != nil {
[0203] return err
[0204] }
[0205] return nil
[0206] }
[0207] / / allowLoopbackTraffic allows all traffic on the local loopback interface
[0208] func allowLoopbackTraffic() error {
[0209] _, err := systemcmd.Execute("iptables -A INPUT -i lo -j ACCEPT")
[0210] if err != nil {
[0211] return err
[0212] }
[0213] _, err = systemcmd.Execute("iptables -A OUTPUT -o lo -j ACCEPT")
[0214] if err != nil {
[0215] return err
[0216] }
[0217] return nil
[0218] }
[0219] / / allowProtocol allows traffic of the specified protocol
[0220] func allowProtocol(protocol string) error {
[0221] _, err := systemcmd.Execute(fmt.Sprintf("iptables -A INPUT -p %s -jACCEPT", protocol))
[0222] if err != nil {
[0223] return err
[0224] }
[0225] _, err = systemcmd.Execute(fmt.Sprintf("iptables -A OUTPUT -p %s -jACCEPT", protocol))
[0226] if err != nil {
[0227] return err
[0228] }
[0229] return nil
[0230] }
[0231] / / denyProtocol denies traffic of the specified protocol
[0232] func denyProtocol(protocol string) error {
[0233] _, err := systemcmd.Execute(fmt.Sprintf("iptables -A INPUT -p %s -jDROP", protocol))
[0234] if err != nil {
[0235] return err
[0236] }
[0237] _, err = systemcmd.Execute(fmt.Sprintf("iptables -A OUTPUT -p %s -jDROP", protocol))
[0238] if err != nil {
[0239] return err
[0240] }
[0241] return nil
[0242] }
[0243] / / denyAllOtherTraffic denies all traffic not explicitly allowed
[0244] func denyAllOtherTraffic() error {
[0245] _, err := systemcmd.Execute("iptables -A INPUT -j DROP")
[0246] if err != nil {
[0247] return err
[0248] }
[0249] _, err = systemcmd.Execute("iptables -A OUTPUT -j DROP")
[0250] if err != nil {
[0251] return err
[0252] }
[0253] return nil
[0254] }".
[0255] See also Figure 6 , Figure 6 This is a flow chart of an embodiment of monitoring a running container according to the present application.
[0256] S501: Monitor the current resource usage parameters of the running container.
[0257] S502: Determine whether the running container has resource overload.
[0258] In this embodiment, when the running container resources are overloaded, step S503 is executed. When the running container resources are overloaded, step S501 is executed.
[0259] Specifically, it can be determined whether the resource usage parameter meets the overload determination condition, wherein the overload determination condition may include a preset condition and / or a user-defined increase condition.
[0260] The preset condition may be that the resource usage parameter exceeds the resource quota.
[0261] The custom increase condition may be that the ratio between the resource usage parameter and the resource quota reaches a first preset value, and the duration of reaching the ratio exceeds a preset duration.
[0262] S503: Use the running container as the observation container and obtain the container group information to which the observation container belongs.
[0263] In this embodiment, the running container with resource overload may be used as an observation container.
[0264] As described in the examples above, the overload determination criteria can include running containers whose resource usage parameters exceed the resource quota as observation containers, and resource types that exceed the resource quota as observation resources. Alternatively, running containers that meet custom ramp-up conditions can be used as observation containers, and resource types that meet the custom ramp-up conditions can be used as observation resources. Custom ramp-up conditions include: the ratio between the resource usage parameter and the resource quota reaches a first preset value, and the duration of this ratio exceeds a preset value.
[0265] S504: Analyze the service corresponding to the container group information as an observation service.
[0266] In this embodiment, you can query the group name and namespace of the container group to which the observed container belongs. The container group is the running container group constructed above. There may be multiple running container groups in a computing cluster, so they are named container groups when performing overall macro monitoring.
[0267] Parse the running information of the observation container based on the group name and the namespace to which it belongs, query the service label in the running information to obtain the service name of the service running in the observation container, and use the service with the service name in the namespace as the observation service.
[0268] S505: Query the current resource configuration of the observation service.
[0269] In this embodiment, the current resource configuration of the observation service may be obtained.
[0270] S506: Perform resource quota increase processing on the observed resources with resource overload.
[0271] In this embodiment, a preset increase is performed on the resource quota of the observed resource within the current resource configuration to form a new resource quota of the observed resource.
[0272] S507: Update the current resource configuration of the observation service.
[0273] In this embodiment, the parameter value of the observed resource in the current resource configuration may be updated to the resource quota obtained in the above steps.
[0274] That is to say, in this embodiment, after the security isolation strategy is initially established, a monitoring feedback module may be established to implement dynamic adjustment of the strategy.
[0275] When the monitoring module detects container resource overload (such as CPU utilization > 80% for 5 consecutive minutes) or security events (such as malicious code injection attempts), it can trigger security permission adjustments and resource updates.
[0276] A resource monitoring module can be built into the control module of the service management device. When the module detects that the running container resources exceed preset rules, it can send resource quota adjustment notifications to system administrators, group administrators, and service owners. At the same time, it can temporarily increase the quota of related resources by approximately 20%, such as increasing the CPU resource quota by 20%, to ensure that the observation container can reliably execute the service tasks of the observation service.
[0277] For example, taking the Kserve type of inference service as an example, Kserve represents an open source model inference platform built on Kubernetes. When the monitoring module resolves that a container in the container group has exceeded the resource usage limit, it uses prometheus (a monitoring module) to reversely query the container group name and its namespace through overload data, calls the Kubernetes interface to view the container group information, and parses the running information of the container group according to the container group name and namespace. It queries the attribute value of the label (labels), that is, the serving.kserve.io / inferenceservice label, to obtain the upper-level inference service name to which the container group belongs, and obtains the configuration information of the inference service under the namespace by querying the database. The corresponding original resource configuration is queried based on the name of the exceeded container. If the CPU exceeds the limit, the original CPU quota will be increased by 20%, while other containers remain unchanged. The specific calculation expression for the initial CPU quota increase can be shown as follows:
[0278] Quota_cpu new = Quota_cpu old * (1 + 20%) Formula 1-1
[0279] Among them, Quota_cpu new Indicates the new resource quota of the CPU; Quota_cpu old Indicates the CPU resource quota without scaling.
[0280] After the adjustment is completed, you can call the patch interface of the Kserve service to trigger the container resource modification of the service resources to take effect, and at the same time change the configuration requirement file.
[0281] Customized increase conditions allow users to configure resource overload rules based on their individual resource usage needs. For example, if CPU utilization exceeds 90% of the resource quota for 30 consecutive minutes, a quota adjustment will be triggered. These can be configured through a Kubernetes configmap and take effect immediately through hot reloading.
[0282] The following example illustrates service security permission management. Multiple security permission levels can be pre-configured, with running containers experiencing security anomalies designated as abnormal containers. If the abnormal container's security permission level is not the lowest, the abnormal container's security permission level can be lowered and updated to the required configuration file. The abnormal container's security permission level can be set to the lowest level, allowing for timely feedback of abnormality information.
[0283] Furthermore, different response strategies can be configured based on the specific event type. When security anomalies of some event types occur, direct anomaly information feedback is provided. When security anomalies of some event types occur, security permission level downgrades can be prioritized.
[0284] See also Figure 7 , Figure 7 This is a flowchart of an embodiment of security authority management of this application.
[0285] S601: Monitor the running container for any security anomalies.
[0286] In this embodiment, when a security anomaly occurs in the running container, step S602 is executed. When no security anomaly occurs in the running container, step S601 is executed.
[0287] Specifically, the security anomaly event includes at least one of an abnormal network connection, abnormal network traffic, and file system tampering. The running container includes a target container.
[0288] S602: The running container is treated as an abnormal container.
[0289] In this embodiment, in response to a security anomaly event, the running container is treated as an abnormal container.
[0290] S603: Identify the event type of the security abnormality event.
[0291] In this embodiment, when the event type is a file type, step S604 is executed. When the event type is a network type, step S606 is executed.
[0292] The file type indicates file system tampering events, such as modifications to inference model files. The network type indicates security anomalies, such as abnormal network connections and abnormal network traffic. Abnormal network connections can include access outside the whitelist, while abnormal network traffic can include a large number of access requests resulting in a significant decrease in service response delay or even no response.
[0293] S604: Determine whether the security permission level of the abnormal container is the lowest level.
[0294] In this embodiment, when the security permission level of the abnormal container is not the lowest level, step S605 is executed. When the security permission level of the abnormal container is the lowest level, step S606 is executed.
[0295] S605: Lower the security permission level of the abnormal container and update it to the required configuration file.
[0296] In this embodiment, in response to the security permission level of the abnormal container not being the lowest level, the security permission level of the abnormal container is lowered and updated to the configuration requirement file.
[0297] In layman's terms, if an exception is triggered in resource permissions (i.e. file type), the operation permissions will be downgraded. For example, if a file that meets the first privacy expectation is tampered with, if it initially has read-write permissions, it will be downgraded to read-only permissions and updated to the container group environment.
[0298] S606: Feedback abnormal information.
[0299] In this embodiment, in response to the security permission level of the abnormal container being the lowest level, abnormal information is fed back.
[0300] Generally speaking, if the security anomaly event is of file type and the security permission level has reached the minimum permission, an immediate notification will be sent to the system administrator, group administrator, and service user to report the anomaly. If the event type is network type, that is, there is a network problem such as abnormal traffic or abnormal network connection, an emergency notification will be sent to the system administrator, group administrator, and service user immediately.
[0301] See also Figure 8 , Figure 8 This is a flowchart of an embodiment of the working principle of the service management model of this application.
[0302] In this embodiment, a service management model may be constructed, wherein the service management model is used to generate a configuration requirement file.
[0303] The service type, resource quota and privacy information of sample services are used to train the service management model and form a configuration rule base.
[0304] In response to the service management model completing training, the service management model and the configuration rule base are used to perform service management, and the service management model is optimized.
[0305] Specifically, the number of abnormal security events can be exposed as a custom metric to Prometheus for processing. Prometheus can collect the custom metric and set the metric name to abnormal_event_total. Based on this, the rate of abnormal events within a preset period, such as 5 minutes, can be evaluated as rate(abnormal_event_total[5m]).
[0306] Pre-training the service management model continuously trains the service management model with data on security incident rates, service types, resource quotas, and configuration requirements before and after service policy changes. This optimizes the configuration rule base and enables self-optimization of policies. The configuration rule base consists of key attributes such as service categories (such as finance), service subcategories (such as banking), service sensitivity, service policies, priorities, and resource allocation.
[0307] A more comprehensive configuration rule base can be established based on sensitive service types, such as finance (which can be further subdivided into banking, securities, and other categories) and healthcare, to improve the predictive accuracy of the service management model. At the same time, as more data is incorporated into the service management model and the configuration rule base self-optimizes, the configuration rule base can be gradually refined and improved to increase the granularity of customized configuration requirement files based on application scenarios.
[0308] In summary, this service management approach can dynamically generate resource allocation priorities and isolation policies based on service priority and privacy. It deeply integrates with the KServe service framework, mapping service metadata to lightweight container runtimes and creating different container runtime isolation policies for services of varying sensitivity. It also deeply modifies the Kata Containers creation process, including Kata Shim, Kata Container, and QEMU, allowing user security policies to be further transmitted to the underlying layer and take effect. Furthermore, it implements real-time monitoring and feedback mechanisms, enabling dynamic adjustment of resource and isolation policies. It also establishes a policy optimization mechanism, enabling self-evolution of policies based on the incidence of security anomalies in actual services.
[0309] The embodiment of the present application provides an inference service method. The following describes in detail the inference service principle of the inference service method in conjunction with the execution process of the inference service method.
[0310] See also Figure 9 , Figure 9 This is a flowchart of an embodiment of the reasoning service method of this application.
[0311] S701: Manage the target reasoning service using a service management method.
[0312] S702: Obtain data to be inferred.
[0313] S703: Input the data to be inferred into the target inference service to obtain the inference output of the target inference service.
[0314] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.
[0315] An embodiment of the present application also provides a service management device.
[0316] In this embodiment, the service management device may include a connection module and a control module.
[0317] The connection module can be connected to a computing cluster, wherein the computing cluster can include one or more computing nodes.
[0318] The control module can be connected to the connection module to implement the service management method or the reasoning service method as described in any of the above embodiments.
[0319] Specifically, the service management method may at least include: obtaining a configuration request for a target service; parsing the privacy information carried in the configuration request to form a configuration requirement file, and mounting the configuration requirement file to a container monitoring process; in response to obtaining a creation request for the target service, obtaining the configuration requirement file from the container monitoring process, controlling the scheduler to select a computing node that is compatible with the configuration requirement file to create a container to form a running container group; wherein the running container group includes at least one target container running the target service; initializing a new virtual machine as a target virtual machine, and controlling the target virtual machine to run the target container to run the target service in the target container.
[0320] The reasoning service method may at least include: managing the target reasoning service using the above-mentioned service management method; obtaining data to be reasoned; and inputting the data to be reasoned into the target reasoning service to obtain the reasoning output of the target reasoning service.
[0321] For descriptions of features in the embodiments corresponding to the service management device, reference can be made to the relevant descriptions of the embodiments corresponding to the service management method and the inference service method, which will not be repeated here.
[0322] An embodiment of the present application also provides an electronic device.
[0323] The electronic device includes: a memory and a processor; the memory is configured to store a computer program; the processor is configured to implement the steps of the aforementioned service management method or the aforementioned inference service method when executing the computer program. The processor is configured to execute the computer program to perform the steps of any of the aforementioned service management method or inference service method embodiments.
[0324] An embodiment of the present application also provides a computer-readable storage medium.
[0325] A computer-readable storage medium stores a computer program, wherein when executed by a processor, the computer program implements the steps of the aforementioned service management method; or implements the steps of the aforementioned inference service method. That is, the computer program is configured to execute the steps of any of the aforementioned service management method or inference service method embodiments when executed.
[0326] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0327] An embodiment of the present application also provides a computer program product.
[0328] The computer program product includes a computer program. When executed by a processor, the computer program implements the steps of the aforementioned service management method; or implements the steps of the aforementioned inference service method. That is, when executed by a processor, the computer program implements the steps of any of the aforementioned service management method or inference service method embodiments.
[0329] Embodiments of the present application also provide another computer program product. The computer program product may include a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the above-mentioned service management method or reasoning service method embodiments.
[0330] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0331] The above is a detailed introduction to a service management method, reasoning service method, electronic device, computer-readable storage medium, and computer program product provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the present application.
Claims
1. A service management method, characterized in that: The service management method includes: Get the configuration request of the target service; Parsing the privacy information carried in the configuration request to form a configuration requirement file, and mounting the configuration requirement file to the container monitoring process; In response to obtaining a creation request for the target service, obtaining the configuration requirement file from the container monitoring process, and controlling the scheduler to select a computing node that is compatible with the configuration requirement file to create a container to form a running container group; wherein the running container group includes at least one target container running the target service; Initializing a new virtual machine as a target virtual machine, controlling the target virtual machine to run the target container, so as to run the target service in the target container; forming a configuration requirement file includes: Obtaining a privacy factor included in the privacy level information; wherein the privacy factor is used to characterize the degree of privacy required by the target service during operation; forming a privacy configuration policy that matches the privacy factor; wherein the privacy configuration policy includes, in response to the target service requesting physical processor resources, providing the target service with a physical processor that matches the privacy factor, for use by the target service; Providing the target service with a physical processor that matches the privacy factor includes: When the privacy factor meets the first privacy expectation, providing the required number of physical processors for the target service as first processors, and controlling the first processors to be isolated from other services; or When the privacy factor meets the second privacy expectation, evaluating the fine-grained number of physical processors matched with the resources requested by the target service, providing the fine-grained number of physical processors as second processors, and controlling the second processors to be shareable with other services; The privacy requirement of the first privacy expectation is higher than the privacy requirement of the second privacy expectation; The parsing of the privacy information carried in the configuration request includes: Obtaining the code annotation of the target service carried in the configuration request; Identifying a priority field and a privacy field preset in the code annotation; Extracting the attribute value of the priority field as a priority factor, and extracting the attribute value of the privacy field as a privacy factor; The priority factor and the privacy factor are used as the privacy level information.
2. The service management method according to claim 1, wherein: The forming of the configuration requirement file includes: Obtain a priority factor included in the privacy information; wherein the priority factor is used to characterize the resource priority of the target service operation; form a priority configuration strategy that matches the priority factor; wherein the priority configuration strategy includes: in response to the current resources of the computing cluster where the target service is deployed being lower than a resource threshold, applying a resource scheduling mode that matches the priority factor to the target service.
3. The service management method according to claim 1, wherein: When the privacy factor meets the first privacy expectation, the method further includes: In response to obtaining service data of the target service, encrypting and storing the service data using an encryption component, configuring network access rules and file access rules as constraint rules, and controlling the target container to comply with the constraint rules when running the target service as a first security configuration; The constraint level of the second security configuration corresponding to the second privacy expectation is lower than the constraint level of the first security configuration.
4. The service management method according to claim 2, wherein: The applying a resource scheduling mode matching the priority factor to the target service includes: When the priority factor meets the first priority expectation, select another service of another priority expectation as the first service, suspend the service process of the first service, so that the target service can obtain the running resources of the first service; or When the priority factor meets the second priority expectation, select a second service and suspend the service process of the second service so that the target service can obtain the running resources of the second service; wherein the second service indicates that the resource priority represented by its priority expectation is lower than that of other services of the second priority expectation; or When the priority factor meets the third priority expectation, controlling the target service not to obtain the operating resources of other services; Among them, the resource priorities of the first priority expectation, the second priority expectation and the third priority expectation decrease in sequence.
5. The service management method according to claim 1, wherein: The controlling the target virtual machine to run the target container so as to run the target service in the target container includes: Triggering the target virtual machine to start, delivering the configuration requirement file to the hosting component of the target virtual machine, and causing the hosting component to recognize the configuration requirement file and form a target virtual interface; Controlling the hosting component process to start, loading a kernel and initializing a virtual machine environment, so as to load the target virtual machine into the kernel; The target container includes a management component of an agent program, and the container monitoring process establishes a remote connection with the management component through a socket interface of the computing node to which it belongs, so as to build a communication link between the inside and outside of the target container.
6. The service management method according to claim 5, characterized in that: The step of causing the hosting component to identify the configuration requirement file and form a target virtual interface includes: Constructing a first virtual interface as the target virtual interface; sending file data to the first virtual interface, causing the first virtual interface to parse the permission configuration statement of the configuration requirement file, converting the permission configuration statement into a permission statement code by a counting method, calling a system management interface to identify the permission statement code to perform permission configuration on the file data; and / or, Construct a second virtual interface as the target virtual interface; obtain the network filtering rules of the configuration requirement file; initialize the network filtering function of the second virtual interface; configure the network filtering function to allow the local loopback interface and the traffic of the first protocol, and reject the traffic of the second protocol and unknown network protocols; wherein the first protocol is the network protocol identified by the network filtering rule for receiving data, and the second protocol is the network protocol identified by the network filtering rule for rejecting data.
7. The service management method according to claim 1, wherein: After running the target service in the target container, the method further includes: Monitoring current resource usage parameters of a running container; wherein the running container includes the target container; The running container whose resource usage parameter exceeds the resource quota is used as an observation container, and the resource type that exceeds the resource quota is used as an observation resource; and / or, the running container that meets the custom increase condition is used as an observation container, and the resource type that meets the custom increase condition is used as the observation resource; wherein the custom increase condition includes: the ratio between the resource usage parameter and the resource quota reaches a first preset value, and the duration of reaching the ratio exceeds the preset duration; Query the group name and namespace of the container group to which the observation container belongs; Parsing the running information of the observation container based on the group name and the namespace to which it belongs, querying the service tag in the running information to obtain the service name of the service running by the observation container; The current resource configuration of the observation service with the service name in the belonging namespace is obtained, and a preset increase is performed on the resource quota of the observation resource in the current resource configuration to form a new resource quota of the observation resource and a new current resource configuration.
8. The service management method according to claim 1 or 7, characterized in that: After running the target service in the target container, the method further includes: Monitoring whether there are any security anomalies in the running container; wherein the security anomaly event includes at least one of abnormal network connection, abnormal network traffic, and file system tampering; the running container includes the target container; In response to the occurrence of the security abnormality event, treating the running container as an abnormal container; Determining whether the security permission level of the abnormal container is the lowest level; In response to the security permission level of the abnormal container being not the lowest level, lowering the security permission level of the abnormal container and updating the configuration requirement file; In response to the security authority level of the abnormal container being the lowest level, abnormal information is fed back.
9. The service management method according to claim 1, wherein: The service management method further includes: Constructing a service management model; wherein the service management model is used to generate a configuration requirements file; Using the service type, resource quota, and privacy information of the sample service to train the service management model and form a configuration rule base; In response to the service management model completing training, the service management model and the configuration rule base are used to perform service management, and the service management model is optimized.
10. A reasoning service method, characterized in that: The reasoning service method includes: Managing a target reasoning service using the service management method according to any one of claims 1 to 9; Obtain the data to be inferred; The data to be inferred is input into the target inference service to obtain the inference output of the target inference service.
11. An electronic device, characterized in that: The electronic device comprises: Memory for storing computer programs; A processor, configured to implement the steps of the service management method according to any one of claims 1 to 9 when executing the computer program; or implement the steps of the reasoning service method according to claim 10.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the service management method according to any one of claims 1 to 9 are implemented; or the steps of the reasoning service method according to claim 10 are implemented.
13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the steps of the service management method according to any one of claims 1 to 9; or implements the steps of the service reasoning method according to claim 10.
Citation Information
Patent Citations
Container creation method and system, electronic equipment and storage medium
CN115904623A
Parameter verification method of Kubernetes object, server and terminal
CN117112124A