Intelligent verification method and system for legality of cloud service orchestration based on knowledge base enhancement

By building a dependency knowledge base and adopting a step-by-step reasoning mechanism, the problems of deep dependency recognition and dynamic reasoning in cloud service orchestration are solved, efficient and accurate cloud resource verification is achieved, and the risk of deployment failure is reduced.

CN120455177AActive Publication Date: 2025-08-08BEIJING MT HIRISUN TECH +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510960368.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-08-08
Estimated Expiration
2045-07-11

AI Technical Summary

Technical Problem

Existing cloud service orchestration verification technology cannot effectively identify deep dependencies, rely on manual experience, and lacks dynamic reasoning capabilities, resulting in deployment failure and security risks.

Method used

Build a list of dependencies and required parameter lists based on the knowledge base, generate a dependency knowledge base by analyzing cloud service provider data, use a step-by-step reasoning mechanism to verify resources, and generate a verification result report.

Benefits of technology

Automatically identify the lack of deep dependence and configuration parameters between cloud resources, improve verification accuracy, reduce the risk of deployment failure, and support multi-cloud platform adaptation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455177A_ABST
    Figure CN120455177A_ABST
Patent Text Reader

Abstract

The invention provides a knowledge base enhancement-based intelligent verification method and system for legality of cloud service arrangement, and the method comprises the steps: constructing a structured dependency knowledge base based on data issued by cloud service providers, taking a cloud service provider identifier as a top-layer namespace, and storing a dependency relationship and necessary parameters in each cloud service provider namespace by taking a resource type as a key name; analyzing a to-be-verified arrangement file, and extracting a resource type, a global resource list and a configuration parameter list; a step-by-step reasoning mechanism is adopted for resource-by-resource verification, a dependency knowledge base is called based on the resource types and the types of cloud service providers to which the resource types belong, and the dependency integrity of a global resource list and the parameter completeness of a configuration parameter list are checked; and generating a verification result report. According to the method, deep dependency deficiency and configuration parameter deficiency among cloud resources can be automatically identified, the verification accuracy is improved, and the deployment failure risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of cloud computing and artificial intelligence technology, and in particular to a method and system for intelligently verifying the legality of cloud service orchestration based on knowledge base enhancement. Background Art

[0002] With the rapid development of cloud computing technology, enterprises are increasingly adopting Infrastructure as Code (IaC) tools (such as Terraform and Pulumi) to automate the deployment and management of cloud resources. This approach, which defines infrastructure through code, significantly improves operational efficiency and reduces manual errors. However, validating the legitimacy of cloud service orchestration becomes a key challenge during actual deployment.

[0003] Currently, mainstream verification methods fall into two main categories: Static syntax checkers (such as YAML / JSON validators) can only verify the syntactic correctness of deployment files and cannot detect deeper dependencies between resources. For example, an Elastic Compute Service (ECS) instance may require dependencies on a Virtual Private Cloud (VPC) and security groups, but static tools cannot determine whether these dependencies are correctly configured in the file. Rule-based verification (such as Open Policy Agent) can check some business rules, but these rules must be manually written, making it difficult to cover complex cloud service dependency scenarios. For example, resource dependencies vary significantly across cloud service providers, making it difficult for rule engines to dynamically adapt.

[0004] It can be seen that the existing verification technology has the following defects: Inability to effectively identify deep dependencies: Cloud resources often have complex dependency chains (such as ECS → VPC → subnet → routing table). Only explicit parameters can be checked, and implicit dependencies cannot be inferred.

[0005] Reliance on manual experience: Rule engines require experts to manually write rules, which makes it difficult to adapt to the rapid updates and iterations of cloud services.

[0006] Lack of dynamic reasoning capabilities: Most verification is done one-time and cannot gradually analyze the root cause of missing dependencies like human experts.

[0007] The above defects often cause enterprises to fail to deploy IaC tools due to missing dependencies or configuration errors, which not only affects efficiency but also may cause security risks. Summary of the Invention

[0008] In view of this, an embodiment of the present invention provides a method and system for intelligent verification of the legality of cloud service orchestration based on knowledge base enhancement to eliminate or improve one or more defects existing in the existing technology and solve the problems existing in the existing verification technology that it cannot effectively identify deep dependencies, relies on manual experience, and lacks dynamic reasoning capabilities.

[0009] In one aspect, the present invention provides a method for intelligently verifying the legality of cloud service orchestration based on knowledge base enhancement, the method comprising the following steps: Parse the cloud service orchestration file to be verified, extract the global resource list and the resource definition of each cloud resource; the resource definition includes the resource type and configuration parameter list; The following verification steps are performed in sequence for each cloud resource in the cloud service orchestration file to be verified: according to the resource type of the current cloud resource and the type of cloud service provider to which it belongs, the corresponding dependency list and required parameter list are obtained from the pre-built dependency knowledge base; whether the global resource list contains all the resources in the dependency list; and whether the configuration parameter list contains all the parameters in the required parameter list; wherein the step of constructing the dependency knowledge base includes: extracting a cloud resource list from the data published by each cloud service provider, extracting the dependency relationship and required parameters of each cloud resource on other resources during deployment from the cloud resource list, and generating a dependency list and a required parameter list; using the cloud service provider identifier as the top-level namespace, under each cloud service provider namespace, using the resource type as the key name, storing the corresponding dependency list and required parameter list to obtain the dependency knowledge base; Summarizes the missing dependencies and required parameters of each cloud resource and generates a verification result report.

[0010] In some embodiments of the present invention, extracting a cloud resource list from data published by each cloud service provider includes: Obtain HTML-formatted document data published by various cloud service providers through a preset automated crawler program; Parsing the structured tags in the document data to extract the cloud resource name and its resource type; wherein the structured tags include an HTML element containing the cloud resource name and a resource type identification element associated with the cloud resource name; The extracted cloud resource names and resource types are summarized and standardized according to the preset naming conventions to generate a machine-readable cloud resource list.

[0011] In some embodiments of the present invention, the dependency relationship and required parameters of each cloud resource on other resources during deployment are extracted from the cloud resource list to generate a dependency relationship list and a required parameter list, including: Using a rule-driven approach, based on preset document structure rules, the dedicated section in the cloud resource list is located; and initial dependency descriptions and parameter lists in the dedicated section are extracted through pattern matching; A semantic recognition method is adopted to parse the initial dependency description and the parameter list through a natural language processing model, to identify mandatory dependencies and required parameters, and to generate the dependency list and the required parameter list.

[0012] In some embodiments of the present invention, the method further includes constructing the dependency knowledge base, and constructing the dependency knowledge base further includes: Combine each resource type with the preset query template to generate structured query instructions; Inputting the structured query instruction into a large language model for processing to obtain the dependency relationship and required parameters of the resource type; Performing consistency check between the dependency relationships and required parameters acquired by the large language model and the dependency relationships and required parameters extracted from the cloud resource list; When the verification is consistent, the dependency relationship and required parameters obtained by the large language model are added to the dependency knowledge base.

[0013] In some embodiments of the present invention, the verification step is performed using a ReAct step-by-step reasoning mechanism driven by a preset template.

[0014] In some embodiments of the present invention, the preset template is constructed based on the following steps: Set the role of the verification execution subject to cloud resource dependency analysis expert; Dual verification task of configuration dependency integrity and parameter integrity; Embedding a typical cloud resource verification case, wherein the typical cloud resource verification case includes resource type identification, complete dependency relationship, required parameters and verification structure report; Predefined validation rules; the validation rules include that cloud resources with dependencies must appear in the global resource list, and mandatory parameters must appear in the configuration parameter list; Specifies a structured output format.

[0015] In some embodiments of the present invention, after summarizing the missing dependencies and required parameters of each cloud resource and generating a verification result report, the method further includes: The validation results are graded based on their impact, including level 1 severity, level 2 severity, and level 3 severity. Level 1 severity indicates missing core dependencies and key security parameters; level 2 severity indicates missing auxiliary function dependencies and non-critical parameters; and level 3 severity indicates suboptimal cloud resource configuration. If it is the first level of severity, a notification of immediate termination of deployment is generated; if it is the second level of severity, a mandatory repair warning is generated; if it is the third level of severity, an optimization suggestion notification is generated.

[0016] On the other hand, the present invention also provides a knowledge base-enhanced cloud service orchestration legality intelligent verification system, comprising a processor, a memory, and a computer program / instruction stored on the memory, wherein the processor is used to execute the computer program / instruction, and when the computer program / instruction is executed, the system implements the steps of any of the methods mentioned above.

[0017] On the other hand, the present invention further provides a computer-readable storage medium having a computer program / instruction stored thereon, which implements the steps of any of the methods mentioned above when executed by a processor.

[0018] On the other hand, the present invention further provides a computer program product, comprising a computer program / instruction, which implements the steps of any of the methods mentioned above when executed by a processor.

[0019] The present invention provides a method and system for intelligent verification of the legality of cloud service orchestration based on knowledge base enhancement, including: constructing a structured dependency knowledge base based on data released by cloud service providers, using cloud service provider identifiers as the top-level namespace, and storing dependency relationships and required parameters under each cloud service provider namespace with resource types as key names; parsing the orchestration file to be verified, extracting resource types, global resource lists, and configuration parameter lists; using a step-by-step reasoning mechanism to verify each resource, calling the dependency knowledge base based on resource types and the type of cloud service provider to which it belongs, checking the dependency integrity of the global resource list and the parameter completeness of the configuration parameter list; and generating a verification result report. The present invention can automatically identify missing deep dependencies and configuration parameters between cloud resources, and solves the problem that traditional tools cannot detect implicit dependencies through intelligent reasoning enhanced by knowledge bases, thereby improving verification accuracy and significantly reducing the risk of deployment failure. At the same time, the system supports multi-cloud platform adaptation and realizes automated legality verification before IaC deployment.

[0020] Additional advantages, objects, and features of the present invention will be set forth in part in the following description and will become apparent to those skilled in the art upon examination of the following or may be learned from practice of the present invention. The objects and other advantages of the present invention may be realized and obtained by the structures particularly pointed out in the description and drawings.

[0021] Those skilled in the art will understand that the purposes and advantages that can be achieved by the present invention are not limited to the above specific descriptions, and the above and other purposes that can be achieved by the present invention will be more clearly understood based on the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings described herein are used to provide a further understanding of the present invention, constitute a part of this application, and do not constitute a limitation of the present invention. In the drawings: Figure 1 Schematic diagram of the steps of a knowledge base-enhanced cloud service orchestration legality intelligent verification method in one embodiment of the present invention.

[0023] Figure 2 This is a flow chart of building a dependent knowledge base in one embodiment of the present invention.

[0024] Figure 3 This is a flow chart of the thinking chain framework verification in one embodiment of the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments and the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0026] It should also be noted that, in order to avoid obscuring the present invention due to unnecessary details, the accompanying drawings only show structures and / or processing steps closely related to the solutions according to the present invention, while other details that are not closely related to the present invention are omitted.

[0027] It should be emphasized that the term "include / comprises" when used herein refers to the existence of features, elements, steps or components, but does not exclude the existence or addition of one or more other features, elements, steps or components.

[0028] It should also be noted that, unless otherwise specified, the term "connection" herein may refer not only to a direct connection but also to an indirect connection involving an intermediate.

[0029] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals represent the same or similar components, or the same or similar steps.

[0030] It should be emphasized here that the step marks mentioned below do not limit the order of the steps, but it should be understood that the steps can be executed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be executed simultaneously.

[0031] In order to solve the problems of existing verification technologies that cannot effectively identify deep dependencies, rely on manual experience, and lack dynamic reasoning capabilities, the present invention provides a cloud service orchestration legality intelligent verification method based on knowledge base enhancement, such as Figure 1 As shown, the method includes the following steps S101 to S103: Step S101: Parse the cloud service orchestration file to be verified and extract the global resource list and resource definition of each cloud resource, wherein the resource definition includes resource type and configuration parameter list.

[0032] Step S102: For each cloud resource in the cloud service orchestration file to be verified, the following verification steps are performed in sequence: based on the resource type of the current cloud resource and the type of cloud service provider it belongs to, the corresponding dependency list and required parameter list are obtained from the pre-built dependency knowledge base; checking whether the global resource list contains all resources in the dependency list; and checking whether the configuration parameter list contains all parameters in the required parameter list. The steps for constructing the dependency knowledge base include: extracting a cloud resource list from the data published by each cloud service provider, extracting the dependencies and required parameters of each cloud resource on other resources during deployment from the cloud resource list, and generating a dependency list and a required parameter list; using the cloud service provider identifier as the top-level namespace, and under each cloud service provider namespace, using the resource type as the key name, storing the corresponding dependency list and required parameter list to obtain the dependency knowledge base.

[0033] Step S103: Summarize the missing dependencies and required parameters of each cloud resource and generate a verification result report.

[0034] In step S101, the cloud service orchestration file to be verified is parsed to extract the global resource list and the resource definition of each cloud resource, wherein the resource definition includes the resource type and the configuration parameter list.

[0035] The cloud service orchestration file to be verified is a declarative configuration file in a preset YAML or JSON format that complies with the specifications of mainstream IaC tools (such as Pulumi and Terraform).

[0036] In some embodiments, a YAML deployment file sample based on the Pulumi specification defines the deployment of various cloud resources including VPC, VSwitch, security group, ECS instance and elastic container instance group. Each resource contains its required key configuration parameters. For example, VPC needs to specify the network segment (cidrBlock), VSwitch needs to be associated with VPC and specify the subnet segment and availability zone, ECS instance must be configured with instance type, image ID and security group, elastic container instance group needs to set CPU, memory and container image, etc. As shown in the following code, through these required parameters, the YAML deployment file fully describes the deployment requirements and mutual dependencies of each resource: name:problem-demo description: Normal deployment configuration resources: vpc-demo: type: alicloud:vpc:Network properties: cidrBlock:10.0.0.0 / 16 vswitch-demo: type: alicloud:vpc:Switch properties: vpcId: ${vpc-demo.id} cidrBlock:10.0.1.0 / 24 zoneId:cn-hangzhou-g sg-demo: type: alicloud:ecs:securityGroup properties: vpcId:${vpc-demo.id} rules: ipProtocol: tcp portRange:22 / 22 cidrIp:0.0.0.0 / 0 ecstest: type: alicloud:ecs:Instance properties: instanceType:ecs.c6.large imageId:centos_7_9_x64_20G_alibase_20230718.vhd instanceName:my-ecs-instance vswitchId:${vswitch-demo.id} securityGroupIds:[${sg-demo.id}] systemDisk: category: cloud_essd size:40 eci-test: type: alicloud:eci:containerGroup properties: containerGroupName:my-eci vSwitchId:Sivswitch-demo.id} securityGroupId: ${sg-demo.id} cpu:2 memory:4 containers: name: nginximage: nginx:latestports: port:80 protocol:TCP In some embodiments, parsing the cloud service orchestration file to be verified to extract the global resource list and resource definition for each cloud resource includes: using a YAML / JSON parser (such as PyYAML) to convert the cloud service orchestration file into an abstract syntax tree (AST) and verifying basic syntax correctness (such as indentation and bracket matching). Identifying the resources top-level node in the document (aliased in different tools, such as Terraform's resource) and collecting the key names (i.e., logical resource names) of all child nodes to obtain the global resource list and resource definition for each cloud resource.

[0037] In step S102, when deploying cloud resources, relying solely on the knowledge stored in the underlying large language model can lead to cognitive biases due to its limited timeliness and generalization capabilities. While obtaining information through the Internet can partially alleviate this problem, it also introduces new uncertainties due to the uncontrollable information source and high processing costs. Therefore, to improve the accuracy and stability of cloud resource dependency judgments, the present invention constructs a structured, authoritative, and scalable dependency knowledge base to provide knowledge support for subsequent thought chain framework reasoning.

[0038] In some embodiments, as Figure 2 The figure shows the flow chart for building a dependency knowledge base, which includes two parts: obtaining a cloud resource list and building a dependency knowledge base.

[0039] Specifically, in the part of obtaining the cloud resource list, official document data released by each cloud service provider is obtained, cloud resource names and resource types are extracted from the official document data, and a cloud resource list is generated.

[0040] In some embodiments, a preset automated crawler program is used to obtain official HTML-formatted document data published by various cloud service providers. The structured markup within the official document data is then parsed to extract cloud resource names and their resource types. The structured markup includes an HTML element containing the cloud resource name and a resource type identifier associated with the cloud resource name. The extracted cloud resource names and resource types are aggregated and standardized according to a preset naming convention to generate a machine-readable cloud resource list. Exemplarily, the preset naming convention is: "cloud service provider identifier: service category: resource type."

[0041] When building the dependency knowledge base, after obtaining the cloud resource list, we extract information from each cloud resource in the list, focusing on two dimensions: the explicit or implicit dependencies of the cloud resource on other resources during deployment (such as networks, security groups, and VPCs); and the key mandatory parameter fields required by the cloud resource in the deployment template (such as vpcId, instanceType, and zoneId). For example, the extracted dependencies and mandatory parameters are combined into metadata in the form of "cloud resource → dependency + mandatory parameters" to build the dependency knowledge base.

[0042] In some embodiments, a rule-driven approach is employed to locate dedicated sections within official HTML documents, such as those for dependency descriptions, prerequisites, and parameter descriptions, based on pre-set document structure rules. Document structure rules can be defined using XPath expressions or CSS selectors. Pattern matching is then used to extract the initial dependency descriptions and parameter lists within the dedicated sections.

[0043] Using semantic recognition methods, a natural language processing model parses the initial dependency description and parameter list to identify mandatory dependencies and required parameters. Mandatory dependencies include ECS instances relying on network resources like VPCs and security groups; mandatory parameters include instance specifications and image IDs. After standardizing naming conventions, formatting, and filtering redundant information, the filtered data is aggregated to generate a list of dependencies and required parameters.

[0044] Based on the generated dependency list and required parameter list, a dependency knowledge base is built.

[0045] In some embodiments, the dependency knowledge base is constructed based on the design principles of "hierarchical organization, clear structure, and strong scalability". Specifically, the dependency knowledge base adopts a hierarchical storage architecture, with the cloud service provider identifier as the top-level namespace. Under each cloud service provider namespace, the resource type is used as the key name to store the corresponding dependency list and required parameter list.

[0046] In some embodiments, the structural design based on the above-mentioned dependency knowledge base can be described as follows: cloudProviders: - providerName: provider_1 resources: - resourceName: resource_1 dependenciesList: [dependency_1, dependency_2, ...] requiredFieldsList: [field_1, field_2, field_3, ...] … - providerName: provider_2 resources: - resourceName: resource_2 dependenciesList: [dependency_1, dependency_2, ...] requiredFieldsList: [field_1, field_2, field_3, ...] … … In some embodiments, a large language model is used to perform polling-based knowledge extraction on the cloud resource list to assist in building a dependency knowledge base, including: combining each resource type with a preset query template to generate a structured query instruction. The structured query instruction is input into the large language model for processing to obtain the dependency relationship and required parameters of the resource type. The dependency relationship and required parameters obtained by the large language model are checked for consistency with the dependency relationship and required parameters extracted from the cloud resource list. When the verification is consistent, the dependency relationship and required parameters obtained by the large language model are added to the dependency knowledge base. Exemplarily, the query template is: "Please list the prerequisite resource dependencies and required configuration parameters that must be met when deploying [resource type] on a cloud service provider. Simply return the format: Dependent resources | resource 1, resource 2, ...; required parameters | parameter 1, parameter 2, ...."

[0047] In step S102, Each cloud resource in the cloud service orchestration file to be verified is verified sequentially using a pre-defined step-by-step reasoning mechanism. This step-by-step reasoning mechanism is based on the Chain-of-Thought (CoT) framework. This framework simulates the logical reasoning path of human experts by breaking down complex tasks into an iterative "observe-think-act-feedback" cycle. For example, the ReAct framework is used.

[0048] In some embodiments, a ReAct thought chain framework driven by preset templates (Prompt).

[0049] In some embodiments, to help the thought chain framework clarify the task, it is necessary to design a prompt with a clear structure and clear goals. In this embodiment, the prompt design principles include: Clarify the role of the verification execution subject: Set the verification execution subject (such as the model) as the "cloud resource dependency analysis expert" role to help the verification execution subject focus on relevant professional domain knowledge.

[0050] Clarify verification tasks: Configure dual verification tasks for dependency integrity and parameter integrity for the verification execution subject. That is, determine whether the cloud resource dependencies in the cloud service orchestration file (deployment file) to be verified are missing, and whether the required parameters are missing.

[0051] Embedding typical cases: Multiple typical cloud resource verification cases (e.g., ECS dependency on VPC) are provided to the verification subject, demonstrating how to identify dependencies and missing required parameters, guiding the verification subject through formal reasoning logic. Typical cloud resource verification cases include information such as resource type identification, complete dependencies, required parameters, and verification structure reports.

[0052] Predefine the fine-grained principle of verification. Cloud resources with dependencies must appear in the global resource list, and mandatory parameters must appear in the configuration parameter list.

[0053] Specified output format: The missing dependent cloud resources and corresponding dependency relationships, missing required parameters, and verification result report must be structured and output.

[0054] To facilitate understanding, examples of each part of Prompt are given: For the part that clarifies the role of the verification execution entity, it can be designed as: "Experts in the field of cloud services and cloud resources."

[0055] For the explicit verification task part, it can be designed as: "Judgment on whether cloud resource dependencies may be missing for a YAML deployment file and whether the attributes filled in the resource fields in the YAML are missing required items."

[0056] For the embedded typical case part, it can be designed as: "The resource field in the YAML file contains an ECS instance. ECS usually depends on a VPC, but there is no VPC in the resource field of the YAML. Therefore, this ECS instance is missing a dependency relative to the YAML and may not be deployed normally. In addition, ECS may have certain required fields, but if there are no corresponding required fields in the ECS parameter configuration, it is considered that the required parameters are missing."

[0057] For the specified output format, you can design the language type and data format, such as outputting a structured verification result report in Chinese.

[0058] Based on the above prompt design, the thinking chain framework can form a standardized judgment process, analyze the actual deployment files one by one, and improve the accuracy and robustness of detection.

[0059] like Figure 3 The figure shows the flow chart for verifying the thinking chain framework, taking the ReAct thinking chain framework as an example.

[0060] The ReAct thinking chain framework receives and parses the pre-designed prompt. Through the role setting and verification task definition in the prompt, it is clear that this task aims to verify the deployment file in two aspects: one is whether the cloud resource dependencies are missing, and the other is whether the required parameters are missing.

[0061] The ReAct thinking chain framework automatically identifies the deployment file fragments attached to the prompt, extracts the resource entries (usually located under the resources node), and performs structured analysis on them to obtain the type of each resource (such as ECS, VPC, RDS, etc.), configuration parameters and their context location.

[0062] The ReAct framework enters the reasoning phase, driven by a cycle of "observation-reflection-action-feedback." Unlike traditional one-time rule matching, the ReAct framework in this embodiment uses inference paths and calls the knowledge base on demand to perform step-by-step deduction and verification.

[0063] Specifically, when the verification execution subject (model) generates an inference path for a certain resource (for example, to determine whether the ECS configuration is complete, the corresponding inference path is "whether the required parameters are present → whether the dependent resources are present", and finally the answer is obtained), whenever external rule support is needed, the model queries the relevant dependency relationships and parameters from the dependency knowledge base.

[0064] In some embodiments, calling the dependency knowledge base on demand includes the following steps: The resource type is extracted based on the cloud service orchestration file (deployment file) to be verified, and the common dependency list and required parameter list of the resource type are obtained from the dependency knowledge base.

[0065] Considering the differences in configuration standards between different cloud service providers, the verification execution entity will infer the type of cloud service provider used in the current deployment based on resource identification and context clues.

[0066] After determining the cloud provider type, retrieve the dependency list and required parameter list for that cloud provider namespace from the dependency knowledge base. Verify that the global resource list of the cloud service orchestration file to be verified contains all resources in the dependency list for that cloud provider type. Verify that the configuration parameter list of the cloud service orchestration file to be verified contains all parameters in the required parameter list for that cloud provider type. During the verification process, any missing dependencies and / or required parameters must be recorded.

[0067] In step S103, the missing dependencies and required parameters of each cloud resource in the cloud service orchestration file to be verified are summarized and a verification result report is generated. If no missing issues are found, a conclusion of "no problem" is output.

[0068] In some embodiments, the impact of the verification results is analyzed based on the verification result report. The verification results are graded based on their impact, including level 1 severity, level 2 severity, and level 3 severity. Level 1 severity indicates missing core dependencies and key security parameters; level 2 severity indicates missing auxiliary function dependencies and non-critical parameters; and level 3 severity indicates suboptimal cloud resource configuration.

[0069] In some embodiments, verification results with different impact levels are handled differently. Specifically, if the severity level is level 1, a notification to immediately terminate deployment is generated; if the severity level is level 2, a mandatory repair warning is generated; and if the severity level is level 3, an optimization suggestion notification is generated.

[0070] Corresponding to the above method, the present invention also provides a knowledge-based enhanced intelligent verification system for cloud service orchestration legitimacy, comprising a processor, a memory, and a computer program / instructions stored in the memory. The processor is configured to execute the computer program / instructions. When the computer program / instructions are executed, the system implements the steps of the knowledge-based enhanced intelligent verification method for cloud service orchestration legitimacy. Corresponding to the above method, the present invention also provides an electronic device, comprising a computer device, the computer device comprising a processor and a memory, the memory storing computer instructions. The processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the electronic device implements the steps of the above method.

[0071] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the aforementioned method. The computer-readable storage medium may be a tangible storage medium, such as a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a floppy disk, a hard disk, a removable storage disk, a CD-ROM, or any other form of storage medium known in the art.

[0072] It should be understood by those skilled in the art that the various exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Whether to implement the system in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention. When implemented in hardware, it may be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The programs or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link via a data signal carried in a carrier wave.

[0073] It should be understood that the present invention is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted. In the above embodiments, several specific steps are described and illustrated as examples. However, the method of the present invention is not limited to the specific steps described and illustrated. Those skilled in the art may make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present invention.

[0074] In the present invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or replace features of other embodiments.

[0075] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations to the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A cloud service orchestration legality intelligent verification method based on knowledge base enhancement, characterized in that: The method comprises the following steps: Parse the cloud service orchestration file to be verified, extract the global resource list and the resource definition of each cloud resource; the resource definition includes the resource type and configuration parameter list; The following verification steps are performed in sequence for each cloud resource in the cloud service orchestration file to be verified: according to the resource type of the current cloud resource and the type of cloud service provider to which it belongs, the corresponding dependency list and required parameter list are obtained from the pre-built dependency knowledge base; whether the global resource list contains all the resources in the dependency list; and whether the configuration parameter list contains all the parameters in the required parameter list; wherein the step of constructing the dependency knowledge base includes: extracting a cloud resource list from the data published by each cloud service provider, extracting the dependency relationship and required parameters of each cloud resource on other resources during deployment from the cloud resource list, and generating a dependency list and a required parameter list; using the cloud service provider identifier as the top-level namespace, under each cloud service provider namespace, using the resource type as the key name, storing the corresponding dependency list and required parameter list to obtain the dependency knowledge base; Summarizes the missing dependencies and required parameters of each cloud resource and generates a verification result report.

2. The method according to claim 1, characterized in that Extract cloud resource lists from data published by various cloud service providers, including: Obtain HTML-formatted document data published by various cloud service providers through a preset automated crawler program; Parsing the structured tags in the document data to extract the cloud resource name and its resource type; wherein the structured tags include an HTML element containing the cloud resource name and a resource type identification element associated with the cloud resource name; The extracted cloud resource names and resource types are summarized and standardized according to the preset naming conventions to generate a machine-readable cloud resource list.

3. The method according to claim 1, characterized in that Dependencies of each cloud resource on other resources and required parameters during deployment are extracted from the cloud resource list to generate a dependency list and a required parameter list, including: Using a rule-driven approach, based on preset document structure rules, the dedicated section in the cloud resource list is located; and initial dependency descriptions and parameter lists in the dedicated section are extracted through pattern matching; A semantic recognition method is adopted to parse the initial dependency description and the parameter list through a natural language processing model, to identify mandatory dependencies and required parameters, and to generate the dependency list and the required parameter list.

4. The method according to claim 1, wherein The method further includes constructing the dependency knowledge base, and constructing the dependency knowledge base further includes: Combine each resource type with the preset query template to generate structured query instructions; Inputting the structured query instruction into a large language model for processing to obtain the dependency relationship and required parameters of the resource type; Performing consistency check between the dependency relationships and required parameters acquired by the large language model and the dependency relationships and required parameters extracted from the cloud resource list; When the verification is consistent, the dependency relationship and required parameters obtained by the large language model are added to the dependency knowledge base.

5. The method according to claim 1, wherein The verification step is performed using a ReAct step-by-step reasoning mechanism driven by a preset template.

6. The method according to claim 5, characterized in that The preset template is constructed based on the following steps: Set the role of the verification execution subject to cloud resource dependency analysis expert; Dual verification task of configuration dependency integrity and parameter integrity; Embedding a typical cloud resource verification case, wherein the typical cloud resource verification case includes resource type identification, complete dependency relationship, required parameters and verification structure report; Predefined validation rules; the validation rules include that cloud resources with dependencies must appear in the global resource list, and mandatory parameters must appear in the configuration parameter list; Specifies a structured output format.

7. The method according to claim 1, characterized in that After summarizing the missing dependencies and required parameters of each cloud resource and generating a verification result report, the method further includes: The validation results are graded based on their impact, including level 1 severity, level 2 severity, and level 3 severity. Level 1 severity indicates missing core dependencies and key security parameters; level 2 severity indicates missing auxiliary function dependencies and non-critical parameters; and level 3 severity indicates suboptimal cloud resource configuration. If it is the first level of severity, a notification of immediate termination of deployment is generated; if it is the second level of severity, a mandatory repair warning is generated; if it is the third level of severity, an optimization suggestion notification is generated.

8. A knowledge base-enhanced cloud service orchestration legality intelligent verification system, comprising a processor, a memory, and a computer program / instruction stored in the memory, characterized in that: The processor is configured to execute the computer program / instructions. When the computer program / instructions are executed, the system implements the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Cloud service testing method and device, electronic equipment and computer storage medium

    CN112579399A

  • Method, device and equipment for editing arrangement template in cloud platform and storage medium

    CN114489781A

  • Cloud resource arrangement processing method and device

    CN116996374A

  • Apparatus and method for verifying cloud service compatibility

    US20170286523A1

  • Hybrid cloud-orchestration map and analyzer

    US20240330720A1