Orchestration system for updating container having application contained therein and orchestration method based thereon
By combining the orchestration system with the OPC-UA standard, the update of containers and operating systems in automated factories is solved, and the problem that container technology cannot support deterministic behavior and firmware updates in the OT field is realized, and a safe update process is achieved to ensure the continuous and safe operation of the factory.
Patent Information
- Application Number
- CN202380085344.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-12
- Filing Date
- 2023-12-07
- Publication Date
- 2025-08-08
AI Technical Summary
In automation plants, prior art cannot avoid jeopardizing the safe operation of the entire plant due to stop and startup when updating containers, especially in the OT field, where container technology cannot support deterministic behavior and firmware update requirements.
A orchestration system is adopted to communicate with multiple automation devices through the public update device, coordinate the update of containers and operating systems, and use the OPC-UA standard to realize a safe update process to ensure that updates are performed without affecting safe operation.
It realizes safe updating of containers and operating systems in automated factories, avoids machine or factory downtime caused by updates, and ensures continuous and safe operation of the factory.
Smart Images

Figure CN120457416A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an orchestration system and an orchestration method for updating an application contained in a container, wherein the orchestration system has at least one automation device connected to an OT network of an automated factory, and the automation device is designed and configured to host and access at least one application contained in the container using a container runtime system. Background Art
[0002] As we all know, container technology ("information technology") is widely used in today's IT world. For automation devices such as PLCs (Programmable Logic Controllers) or I / O modules (Input / Output Modules), frequency converters, robots, network devices, power supplies, and other components used in automation technology, especially network components in factories, OPC UA ("Open Platform Communications Unified Architecture"; a standard for data exchange as a platform-independent, service-oriented architecture) has become an established standard for modeling and communication. On the other hand, container technology, while long a non-issue, is now gaining increasing acceptance in the automation market. While OPC UA and container technology are used in automation devices, they have until now been implemented independently.
[0003] The main advantage of container technology is that, in a runtime system, individual applications (especially software programs) can be isolated from one another in containers and called for processing, and available system resources (especially hardware resources) can be allocated individually and flexibly, thereby efficiently utilizing all resources. To achieve isolated access and individual allocation, such systems typically include a so-called container engine—administrative and management software designed specifically for this purpose. Therefore, the applications contained in each container typically represent only a small part of a larger application and are often referred to as microservices. Therefore, multiple containers are often required to fully provide a large application, but these containers can be flexibly combined and managed using simple mechanisms—that is, they can be orchestrated—which is another major advantage of container technology. Since all of this is also useful in the OT field ("Operations Technology" / automation technology), separate automation devices already exist that support container technology.
[0004] For example, in EP 4064637 A1, a method is proposed to facilitate user provision of such a container, by means of which the information required for restarting and executing the application contained in the container can be provided only after the container is installed in a device, which is intended and configured as an edge device for executing the application and does not need to be known at the time of development.
[0005] The internationally standardized ISA95 model, which divides automation into five levels, is used to distinguish between IT and OT within the context of this invention. The top two levels include the parent company level and the operations management level. Digital processes at these levels are assigned to IT and carried out within a dedicated IT network. Automation processes at the three lower levels—process control, control, and field levels—are controlled via appropriately configured OT networks.
[0006] Therefore, pure container technology is not an ideal choice for automation. The advantages of container orchestrators in the IT world can also mean disadvantages in the OT world. In the OT world, deterministic behavior is required, and automated stop / start and updates can hinder the safe operation of machines or factories. Machines generally cannot be stopped or restarted at random times. Furthermore, in the OT world, device firmware often requires updates to maintain network security, which often requires a device reboot, and container technology does not support such updates.
[0007] In EP 3 998 529 A1, a highly complex container orchestration system is proposed, which has a cluster of computing nodes for updating multiple control systems and thereby controlling multiple operations of multiple OT devices. The system is proposed to be used in industrial systems to move operations between control systems and / or OT devices so that the update process can be performed within the runtime system, so that some control systems and / or OT devices can be updated while they are offline, and other control systems and / or OT devices remain online to perform the corresponding operations.
[0008] EP 4 064 045 A1 proposes updating process software in real time using multiple software containers of deployment units provided on a single physical host node.
[0009] Here, a first software container is provided for executing a process application for controlling a process device; a second software container is provided as an execution manager for receiving updated versions of the process application and / or the first software container; and a third software container is provided in which the updated version is initialized.
[0010] Subsequently, an application state of the first process application is determined under the control of the execution manager and transferred from the first software container to the third software container, an update is then also performed with the aid of the third software container using the received application state, and the first software container is then instructed to stop writing output signals to the process device and the third software container is instructed to write output signals to the process device. Summary of the Invention
[0011] The object of the present invention is to demonstrate a new technical approach by means of which, when updating industrial automation devices in an automation plant (such as programmable logic controllers, IO modules (input / output modules), frequency converters, robots, network devices, power supplies or other components used in automation technology), the corresponding automation processes to be controlled can be integrated, in particular in order not to jeopardize the safe operation of the entire automation plant due to stopping and starting during the updating process to be performed.
[0012] The solution according to the invention is provided by a system having the features of claim 1 and a method according to claim 6. Useful embodiments of the invention are subject matter of the dependent claims.
[0013] Useful and advantageous further developments are the subject matter of the respectively dependent claims.
[0014] The present invention therefore proposes an orchestration system, in particular for updating containers containing applications, comprising a plurality of automation devices connected to an OT network of an automation plant, wherein each of the plurality of automation devices is designed and configured to host and access the application contained in the container using a container runtime system. Furthermore, the orchestration system according to the invention comprises a common update device, which is configured to update the container and to communicate with the runtime system of each of the plurality of automation devices for this purpose, and each of the plurality of automation devices furthermore comprises a control device for controlling the automation of the automation device to be implemented in each case within the context of the automation plant, as well as a server unit which communicates with the control device and is further connected to a client unit of the update device via a client / server interface.
[0015] With the help of this update device (which is not implemented on the individual automation devices themselves, but rather as a common update device for all multiple automation devices connected to the OT network of an automation plant, which is included in the orchestration system), it is possible, on the one hand, to coordinate the updating of multiple containers containing applications hosted on the multiple automation devices using corresponding container runtime systems, and in particular, to implement update plans stored in the update device in a correspondingly coordinated manner. On the other hand, using the client unit provided in the update device, it is also possible to include process control (i.e., in particular, the operating states of the individual control devices and the start and stop procedures) in the coordination of the updates to be performed via the server unit additionally installed in all the hosted automation devices. This makes it possible, in particular, to wait for a time when an update can be performed without jeopardizing safe operation and / or to actively intervene in the control of the automation to be implemented in the context of the factory automation plant, for example, to convert the entire process or the entire automation plant, or even its subprocesses or individual automation devices, into a safe operating state before initiating and subsequently implementing the update.
[0016] Furthermore, in such an orchestration system according to the invention, each server unit preferably communicates with the operating system of the corresponding automation device in order to be able to coordinate and securely perform not only the updating of the container but also the updating of the firmware of the corresponding operating system, in particular according to an update plan stored in the update device.
[0017] Furthermore, configuring the server unit as an OPC-UA server, the client / server interface as an OPC-UA interface, and the client unit as an OPC-UA client has proven particularly suitable for the orchestration system according to the invention.
[0018] Therefore, the present invention proposes an orchestration method for updating a container containing an application, wherein the application is hosted in a plurality of automation devices connected to an OT network of an automation plant for accessing the application using a container runtime system, for which purpose the runtime system of each of the plurality of automation devices is arranged in a communication link with a common update device arranged for implementing the container update, and for this purpose a control device housed in each of the plurality of automation devices for controlling the automation of the automation devices to be implemented in the context of the automation plant is arranged in a communication link with a server unit, which is additionally housed in each of the plurality of automation devices and is connected to a client unit of the common update device via a client / server interface.
[0019] According to the present invention, in order to update the container containing the application for at least each of the multiple automation devices involved in this process, before initiating the update, the update device for the control device can send a first update signal to the server unit connected to the client / server interface via the client / server interface, and thereby forward the first update signal to the control device to stop the automation to be implemented, in particular by controlling the automation of the automation device to be implemented in the environment of the automation plant to ensure the safety state of the automation device or the safety state of the area of the automation plant beyond the automation device, and after sending feedback on the successful stop of the automation to be implemented to the update device, the update device sends a second update signal to the runtime system to initiate the update. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The features and advantages of the present invention which have been outlined above, as well as other features and advantages of the present invention, will become more apparent from the following description, by way of examples of preferred and further embodiments, with reference to the accompanying drawings, in which:
[0021] Figure 1 is a highly simplified overview of an exemplary orchestration system according to a preferred embodiment of the present invention. DETAILED DESCRIPTION
[0022] References below Figure 1 Based on this figure, for the sake of clarity, preferred embodiments of an orchestration system according to the present invention, in particular for updating containers of applications contained therein, and an orchestration method based thereon and examples of their further development are outlined and shown in highly simplified form.
[0023] Figure 1A highly simplified overview of an orchestration system is shown, comprising multiple automation devices 4, 4n connected to an OT network 20 of an automated plant (not shown in detail for clarity). Automation device 4n is only partially shown. In a preferred embodiment, additional automation devices may be connected, as indicated by the dots above and to the right of the automation devices. The number of such automation devices included in the orchestration system is therefore conveniently not limited to just one, but rather to at least two, and preferably a plurality exceeding this number. As shown by automation device 4, each of these automation devices 4, 4n is designed and configured to host and access at least one application contained within a container 6, 6m using a container runtime system 5. Since, as mentioned at the outset, multiple containers are often required to fully provision large applications, such automation devices 4, 4n, as shown in the example of automation device 4, typically host multiple containers 6, 6m (particularly application-related containers) containing applications for access, particularly so that they can be individually and efficiently invoked for processing using the container runtime system 5.
[0024] In addition to the plurality of automation devices 4, 4n, the orchestration system also includes an update device 1, which is configured to update the container 6, 6m and, for this purpose, communicates with the runtime system 5 of each of the plurality of automation devices 4, 4n, as described in more detail below. Thus, container updates are initiated or coordinated from outside the automation device, rather than by a unit hosted by the automation device. The update device 1 may include, in particular, a control and evaluation unit (in particular, in the form of a microcontroller) and a storage device, which may be arranged externally and / or internally to the microcontroller and may contain software, including multiple programs, firmware, and / or operating systems, that can implement various protocols (in particular, communication protocols) and / or control and evaluation routines. For example, update plans may also be stored in the memory.
[0025] However, each automation device 4, 4n accommodates a control device 11, which is used to control the automation to be realized in the environment of an automated plant and, within the scope of the present invention, also accommodates a server unit 12, which communicates with the control device 11 and is connected to the client unit 1A of the update device 1 via a client / server interface 2.
[0026] If an update of one or more containers is now to be performed, this can in particular be specified manually by the user or automatically, for example after a certain time period and / or according to a stored update plan, or can also be specified to the update device by other signaling, however, the type of specification thus made is not the subject of the present invention, the update device 1 being suitably configured to implement such an update of the container 6, 6m containing the application with respect to at least each automation device of the plurality of automation devices involved, i.e. in particular fundamentally affected within the context of the update, so that before initiating the update, a first update signal AS1 is sent from the update device 1 for the corresponding control device 11 via the corresponding client / server interface 2 to the corresponding server unit 12 connected to the client / server interface, which then forwards the signal to the control device 11 in order to stop the automation to be implemented, i.e. in particular by controlling the automation of the automation device to be implemented in the context of the automation plant, in order to ensure the safe state of the automation device or, specifically depending on the application, the safe state of the area of the automation system outside the automation device.
[0027] After the feedback RM1 reaches the updating device 1 (i.e., specifically, starting from the respective control device 11 for each automation device involved in this process, to the respective server unit 12 connected to the control device, and from there via the respective client / server interface 2 to the updating device 1), the updating device 1 sends a second update signal AS2 regarding the cessation of the automation to be implemented to the respective runtime system 5 in order to initiate the update.
[0028] like Figure 1 It can be seen in FIG. 1 that within the scope of the invention, two different, complementary or alternative communication connections are conceivable for establishing a communication link between the update device 1 and each runtime system 5 .
[0029] On the one hand, the update device 1, in particular the client unit 1A, can be connected to the runtime system 5 via a container interface 14. The second update signal AS2 sent via this additional container interface 14 is Figure 1 Marked as AS2'.
[0030] On the other hand, the server unit 12 can also be connected to the runtime system 5 via the container management interface 10. The second update signal AS2 sent via this interface is Figure 1 is marked as AS2".
[0031] The interface set up for each communication connection can include hardware and / or software for implementing the corresponding communication protocol and transmitting the corresponding communication signals between the units involved (i.e., in particular between the update device and the runtime system, the client unit and the server unit, and the server unit and the runtime system), and can be set up wirelessly (e.g. via radio) or wiredly (e.g. via copper cable or optical fiber).
[0032] Here, the interfaces are suitably arranged so that, for example, the update device can use them to query the container status, a list of containers containing currently running versions is available to the update device 1, and in response to the query of the update device, the update of the container can be initiated (i.e., in particular, it can be initiated), the update of the container can be stopped (i.e., in particular, access to the container can be blocked), and / or the updated container can be restarted (i.e., in particular, access to the container can be enabled again).
[0033] As for the update itself, as is known, the container image or memory image of the container intended for the update can be provided on a server 8 as a source (e.g. a register server having a plurality of registers or memory areas 8A), which for this purpose communicates with the runtime system 5, in particular via e.g. Figure 1 A correspondingly configured container register interface 7 is shown in order to transmit a corresponding container memory image 9 to the runtime system in response to an initiated container update. Additionally or alternatively, it can also be provided that such an image is available in a storage area of the updating device 1 itself and is transmitted from there to the corresponding automation device 4, 4n and to the runtime system 5, so that in this alternative case, a separate server 8 as a source is not required.
[0034] In a preferred embodiment, in order to implement the update, the update device 1 therefore also transmits at least one version name of the new memory image 9 of the at least one container to be updated to the corresponding runtime system 5, specifically as part of the update signal AS2 or by means of a separate communication signal provided for this purpose (not shown in the figure for the sake of clarity), at least initiating the transmission of the new memory image 9 of each of the at least one container to be updated to the corresponding runtime system 5, and stopping the execution of each of the at least one container to be updated 6. Depending on the embodiment, the update signal AS2 itself may also contain corresponding signal components for initiating and stopping, or at least one other communication signal may also be provided, although this is not shown in the figure for the sake of clarity.
[0035] The same applies to the preferred initiation of the updating of the at least one container 6 with a new memory image by the updating device 1 after the update has been completed, ie in particular after a corresponding feedback from the runtime system 5 to the updating device.
[0036] like Figure 1 As further shown in the figure, in a preferred embodiment of the present invention, each server unit also communicates with the operating system 13 of the corresponding automation device. Thus, according to the present invention, the update device 1 commonly connected to the automation devices 4, 4n can preferably be used not only to perform ordered updates of containers, but also to perform required or even necessary updates to the firmware of the corresponding operating system. Specifically, since, as mentioned at the outset, OPC UA is an established standard for modeling and communication in automation technology, and it is well known that updates to device firmware can already be controlled via this standard, the orchestration system according to the present invention has been shown to be particularly suitable for configuring the server unit 12 as an OPC UA server, the client / server interface 2 as an OPC UA interface, and the client unit 1A as an OPC UA client. Thus, in a particularly convenient implementation of the present invention, OPC UA and container technologies can be used jointly or in a complementary manner.
[0037] After sending the above-mentioned feedback RM1 regarding the successful stop of the automation to be implemented to the update device 1, the third update signal AS3 can also be sent, for example, from the update device 1 via the client / server interface 2 to the server unit 12 of at least one of the automation devices 4, 4n connected to the OT network, so as to implement the update of the operating system firmware of the automation device.
[0038] Thus, for the control device 11, a fourth update signal AS4 can be sent by the update device 1 via the client / server interface 2 to the server unit 12 connected to the client / server interface and forwarded by the server unit 12 to the control device 11 for restarting the automation to be realized, but according to a preferred further development, conveniently only after feedback RM2 that all updates to be realized have been completely successful.
[0039] Thus, with the aid of the client unit 1A provided in the update device 1, not only can the process control (i.e., in particular the operating states and start and stop processes of the corresponding control devices 11) be additionally included in the coordination of the container update to be carried out via the server unit 12 additionally accommodated in all automation devices 4, 4n, but preferably also the firmware update can be included in the update process.
[0040] In summary, a possible process using the orchestration system according to the present invention can be briefly outlined, for example, as follows.
[0041] According to the implementation, the update device 1 may obtain a list of containers containing currently running versions, specifically via the client / server interface 2 and the container management interface 10 or via the container interface 14 .
[0042] If an update is now to be carried out, the update device 1 stops the machine / plant via the client / server interface 2 and then, depending on the implementation, also stops the update container 6 via the client / server interface 2 and the container management interface 10 or via the container interface 14 .
[0043] Depending on the implementation, before or only after this stop, the version name of the new container image 9 is transferred from the update device 1 (in particular, from the client unit 1A) to the runtime system 5 of the corresponding automation device 4, 4n, and a transfer of the new image 9 from the storage area 8A of the server 8 to the runtime system 5 of the corresponding automation device 4, 4n is initiated. Depending on the implementation, this can be done via the client / server interface 2 and the container management interface 10 or via the container interface 14. As already mentioned, it can also be provided, in addition or as an alternative, that such an image 9 is stored in the storage area of the update device 1 itself and transferred from there to the corresponding automation device 4, 4n and runtime system 5, thereby eliminating the need for a separate server 8 as a source in this alternative.
[0044] Depending on the implementation, the update device 1 starts the container 6 with the new image 9, i.e. via the client / server interface 2 and the container management interface 10 or via the container interface 14. Of course, multiple containers 6, 6m and even multiple automation devices 4, 4n can also be updated accordingly.
[0045] The machine / plant is started automatically or explicitly by the updating device 1 via the client / server interface 2 .
[0046] Furthermore, the update device 1 can also perform a firmware update on the operating system 13 of one or more automation devices 4 , 4 n , for example, before starting a new (ie updated) container, conveniently performing the necessary firmware update on the container to be updated or updated via known OPC UA mechanisms.
[0047] As can also be seen from the above description, the method according to the present invention is specifically provided by a suitable combination of hardware and software, so that the necessary software can also be run on existing hardware (such as existing processors). However, based on a reasonable understanding of the above description, the program-specific implementation, in particular the program-specific configuration of the devices and interfaces involved in the context of the present invention, is within the knowledge and ability of the commissioned programmer.
Claims
1. An orchestration system, particularly for updating a container containing an application, comprising: a plurality of automation devices (4, 4n) connected to an OT network (20) of an automated factory, wherein each of the plurality of automation devices is intended and arranged to host and access at least one application contained in a container (6, 6m) using a container runtime system (5), as well as, an updating device (1) which is configured to enable an update of the container (6) and, for this purpose, to communicate with the runtime system (5) of each automation device (4, 4n) of the plurality of automation devices, Each of the plurality of automation devices (4, 4n) further comprises a control device (11) for controlling the automation of the automation device (4) to be implemented in the context of the automation plant, and a server unit (12), the server unit communicating with the control device (11) and being connected to a client unit (1A) of the updating device (1) via a client / server interface (2).
2. The orchestration system according to claim 1, wherein each server unit further communicates with an operating system (13) of a corresponding automation device.
3. The orchestration system according to claim 1 or 2, wherein the server unit (12) is configured as an OPC-UA server, the client / server interface (2) is configured as an OPC-UA interface, and the client unit (1A) is configured as an OPC-UA client.
4. The orchestration system according to claim 1 , wherein in order to establish a communication link between the update device ( 1 ) and each runtime system ( 5 ), the server unit (12) is connected to the corresponding runtime system (5) via a container management interface (10), the container management interface being configured to establish a communication link between the update device (1) and the corresponding runtime system, to provide a list of containers including currently running versions, to query container status, to initiate an update of a container, to stop updating a container and / or to start an updated container, and / or - the update device (1) is connected to the corresponding runtime system (5) via a container interface (14), the container interface being configured to establish a communication link between the update device and the corresponding runtime system, to provide a list of the containers including the currently running versions, to query the container status, to initiate an update of the container, to stop updating a container and / or to start an updated container.
5. The orchestration system according to any one of the preceding claims, further comprising: At least one server (8) in communication with the corresponding runtime system (5) for providing a container memory image (9, 9k).
6. An orchestration method for updating a container (6, 6m) containing an application, the application being hosted in a plurality of automation devices (4, 4n) connected to an OT network (20) of an automation factory, for accessing the application using a container runtime system (5), wherein: An updating device (1) is arranged to implement an update of a container (6, 6m) having an application contained in the container and hosted in the plurality of at least one automation device, and the updating device is arranged to be communicatively linked to the runtime system (5) of each automation device (4, 4n) of the plurality of automation devices, and wherein In each of the plurality of at least one automation devices (4, 4n), a control device (11) is further hosted, the control device being used to control the automation of the automation device (4) to be implemented in the context of the automation plant, and a server unit (12), the server unit being arranged in a communication link with the control device (11) and connected to a client unit (1A) of the updating device (1) via a client / server interface (2), The method further comprises the following steps: In order to implement an update for at least each automation device (4, 4n) of the plurality of automation devices involved, and before initiating the update, a first update signal (AS1) is sent from the update device (1) for the control device (11) via the client / server interface (2) to the server unit (12) connected to the client / server interface and forwarded by the server unit to the control device (11), specifically for stopping the automation to be implemented, in particular by controlling the automation of the automation device (4, 4n) to be implemented in the environment of the automation plant in order to ensure a safe state of at least the automation device (4, 4n) or a safe state of an area of the automation system beyond the automation device (4, 4n), After sending feedback (RM1) to the update device (1) regarding the successful stop of the automation to be implemented, the update device (1) sends a second update signal (AS2', AS2") to the runtime system (5) to initiate the update.
7. The arrangement method according to claim 6, wherein the updating device (1) for implementing the updating further comprises - transmitting the version name of the new memory image (9) of at least one container to be updated to the corresponding runtime system (5), - initiating the transfer of the new memory image (9) of each of the at least one container to be updated to the corresponding runtime system (5), and - stopping the execution of each of the at least one container to be updated (6).
8. The orchestration method according to claim 7, wherein after the update is implemented, the update device (1) further starts updating at least one container (6) with a new memory image.
9. The orchestration method according to claim 6 , wherein after sending feedback (RM1) to the update device (1) regarding the successful stopping of the automation to be implemented, a third update signal (AS3) is sent from the update device (1) via the client / server interface (2) to the server unit (12) of at least one of the automation devices (4) connected to the OT network (12) in order to implement the update of the operating system firmware of the automation device.
10. An orchestration method according to any one of claims 6 to 9, wherein, after feedback (RM2) regarding the complete success of all updates to be implemented, a fourth update signal (AS4) is sent from the update device (1) for the control device (11) via the client / server interface (2) to the server unit (12) connected to the client / server interface and forwarded by the server unit to the control device (11), i.e., for restarting the automation to be implemented.
Citation Information
Patent Citations
Updating operational technology devices using container orchestration systems
EP3998529A1
Method for real-time updating of process software
EP4064045A1
Method and device for configuring an application
EP4064637A1