Mirror image pulling method and device of container node, electronic equipment and storage medium

By introducing a proxy plug-in into the container node, obtaining the list of preferred nodes and pulling the mirror file from it, the problem of slow image pulling speed in edge computing scenarios is solved, and efficient image transmission and cost reduction are achieved.

CN120540753AInactive Publication Date: 2025-08-26WUHAN SHENZHIDU TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511038030.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-08-26
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In cross-domain and cross-regional edge computing scenarios, container nodes are slow to pull images to container mirror warehouses, which is subject to network bandwidth and pressure on mirror warehouse servers.

Method used

By introducing proxy plug-ins into container nodes, a list of preferred nodes in the target container cluster that meets predetermined conditions and pulling mirror files from these nodes is reduced to the dependence on centralized mirror warehouses, and using proxy plug-ins to replace the mirror pull service during container runtime to achieve efficient transmission of mirror files.

Benefits of technology

It improves the efficiency of mirror pulling, reduces the data processing pressure and traffic costs of mirror warehouses, reduces the cost of mirror pulling, and reduces the computing resource consumption of container nodes, solving the problem of slow mirror pulling speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120540753A_ABST
    Figure CN120540753A_ABST
Patent Text Reader

Abstract

The invention relates to a mirror image pulling method and device of a container node, electronic equipment and a storage medium, and belongs to the technical field of container, the method comprises the following steps: in response to a pulling request for a target mirror image file, obtaining a preferred node list for a current container node through a preset proxy plug-in in the current container node, the preferred node list comprises container nodes in the target container cluster, wherein the communication speed between the container nodes and the current container node meets a preset condition; searching a target container node in which the target mirror image file is stored from the preferred node list through the proxy plug-in; and pulling the target mirror image file from the target container node through the proxy plug-in. The problem that the speed is low when the container node pulls the mirror image from the container mirror image warehouse is solved, and the proxy plug-in is configured as a mirror image pulling tool when the container of the current container node runs, so that invasion to codes when the container runs can be reduced, computing resource consumption of the current container node is reduced, and the mirror image pulling speed is further increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of container technology, and in particular to a method, device, electronic device, and storage medium for pulling images of a container node. Background Art

[0002] The mainstream deployment method for modern server-side applications is containerized deployment. Commonly used tools include container runtimes such as Docker and iSula, as well as a series of container orchestration platforms such as Kubernetes, such as OpenShift and UCCPS (Uniontech Container Cloud Platform Solution) based on Kubernetes.

[0003] The construction and service deployment of these platforms require the use of Docker images, which are typically hosted on container image repositories such as docker.io and quay.io. Since most image repository servers are located overseas, pulling images in China often encounters slow speeds and various limitations.

[0004] Deploying a private container image repository can effectively increase the speed of image pulls. However, when cluster nodes span multiple cities, they are still limited by the network bandwidth of local operators. This delay is particularly significant in edge computing scenarios. Summary of the Invention

[0005] The present disclosure provides a method, device, electronic device, and storage medium for pulling images from a container node, to at least solve the problem in the related art that container nodes are slow when pulling images from a container image repository.

[0006] According to a first aspect of an embodiment of the present disclosure, a method for pulling an image of a container node is provided, comprising: in response to a pull request for a target image file, obtaining a preferred node list for the current container node through a proxy plug-in preset in the current container node, wherein the preferred node list includes container nodes in a target container cluster whose communication speed with the current container node meets a predetermined condition; searching for a target container node storing the target image file from the preferred node list through the proxy plug-in; pulling the target image file from the target container node through the proxy plug-in; wherein the proxy plug-in is configured as an image pulling tool for the container runtime of the current container node.

[0007] Optionally, pulling the target image file from the target container node through the proxy plug-in includes: pulling the target image file from a proxy plug-in in the target container node through the proxy plug-in.

[0008] Optionally, searching for the target container node storing the target image file from the preferred node list through the proxy plug-in includes: obtaining, from a container server through the proxy plug-in, description information of the image file stored in the container node in the preferred node list, wherein the description information stored by the container server is obtained from the proxy plug-in of each container node in the target container cluster; and searching for the target container node storing the target image file from the preferred node list through the proxy plug-in based on the description information.

[0009] Optionally, the image pulling method according to an embodiment of the present disclosure also includes: using the proxy plug-in to save the target image file in the specified format of the container runtime of the current container node when the container runtime of the target container node is of a different type from the container runtime of the current container node.

[0010] Optionally, the preferred node list is determined by the proxy plug-in performing the following steps: detecting network quality indicators between multiple container nodes in the target container cluster and the current container node, and obtaining reference information of the alternative container nodes, wherein the reference information includes at least one of the following: hardware resource data, network topology relationship, node IP address; from the multiple container nodes, determining a container node whose network quality indicator meets the preset network conditions and whose reference information meets the preset reference conditions as the alternative container node; determining a score of the alternative container node based on the network quality indicator and the reference information; and screening a container node from the alternative container node based on the score, and adding it to the preferred node list.

[0011] Optionally, the image pulling method according to the embodiment of the present disclosure further includes: pulling the target image file from the image repository when no container node storing the target image file is found in the preferred node list by the proxy plug-in.

[0012] According to a second aspect of an embodiment of the present disclosure, there is provided an image pulling device for a container node, comprising: an acquisition unit, configured to, in response to a pull request for a target image file, acquire a preferred node list for the current container node through a proxy plug-in preset in the current container node, wherein the preferred node list includes container nodes in a target container cluster whose communication speed with the current container node meets a predetermined condition; a search unit, configured to search for a target container node storing the target image file from the preferred node list through the proxy plug-in; a first pulling unit, configured to pull the target image file from the target container node through the proxy plug-in; wherein the proxy plug-in is configured as an image pulling tool during container runtime of the current container node.

[0013] Optionally, the first pulling unit is further configured to pull the target image file from a proxy plug-in in the target container node through the proxy plug-in.

[0014] Optionally, the search unit is further configured to: obtain, from the container server through the proxy plug-in, description information of the image file stored in the container node in the preferred node list, wherein the description information stored in the container server is obtained from the proxy plug-in of each container node in the target container cluster; and search, through the proxy plug-in, for the target container node storing the target image file from the preferred node list based on the description information.

[0015] Optionally, the image pulling device according to an embodiment of the present disclosure further includes: a storage unit, configured to save the target image file in the prescribed format of the container runtime of the current container node through the proxy plug-in when the container runtime of the target container node is of a different type from the container runtime of the current container node.

[0016] Optionally, the preferred node list is determined by the proxy plug-in performing the following steps: detecting network quality indicators between multiple container nodes in the target container cluster and the current container node, and obtaining reference information of the alternative container nodes, wherein the reference information includes at least one of the following: hardware resource data, network topology relationship, node IP address; from the multiple container nodes, determining a container node whose network quality indicator meets the preset network conditions and whose reference information meets the preset reference conditions as the alternative container node; determining a score of the alternative container node based on the network quality indicator and the reference information; and screening a container node from the alternative container node based on the score, and adding it to the preferred node list.

[0017] Optionally, the image pulling device according to an embodiment of the present disclosure further includes: a second pulling unit, configured to pull the target image file from the image repository if the container node storing the target image file is not found in the preferred node list through the proxy plug-in.

[0018] According to a third aspect of an embodiment of the present disclosure, an electronic device is provided, comprising: at least one processor; and at least one memory storing computer-executable instructions, wherein the computer-executable instructions, when executed by the at least one processor, prompt the at least one processor to execute the image pulling method for a container node according to an exemplary embodiment of the present disclosure.

[0019] According to a fourth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided. When instructions in the computer-readable storage medium are executed by at least one processor, the at least one processor is prompted to execute the image pulling method for a container node according to an exemplary embodiment of the present disclosure.

[0020] According to a fifth aspect of an embodiment of the present disclosure, a computer program product is provided, comprising computer instructions. When the computer instructions are executed by at least one processor, the at least one processor is prompted to execute the image pulling method for a container node according to an exemplary embodiment of the present disclosure.

[0021] The technical solutions provided by the embodiments of the present disclosure bring at least the following beneficial effects: According to the image pulling method, device, electronic device and storage medium of the container node disclosed in the present invention, by obtaining a preferred node list consisting of container nodes that meet predetermined conditions in the target container cluster for the current container node, and pulling the target image file required by the current container node from the container nodes in the list, the image pulling efficiency can be effectively improved, the dependence on the centralized image repository can be reduced, and the problem of slow image pulling in cross-domain and cross-regional edge computing scenarios can be effectively solved.

[0022] At the same time, all nodes (including edge nodes) in the existing Kubernetes cluster pull images independently. For example, if 100 nodes need to pull a 1Gb Docker image at the same time, the image repository server will be overloaded with 100Gbps. In a shared cloud environment with traffic-based billing, the traffic cost is 100 times that of pulling a single image. The present disclosure can reduce the data processing pressure on the image repository by redirecting traffic that should have been pulled from the image repository to container nodes in the preferred node list, effectively reducing the request traffic to the image repository and lowering the cost of pulling images.

[0023] Furthermore, the present disclosure also provides a special proxy plug-in to perform the above operations, and configures the proxy plug-in as an image pulling tool for the container runtime of the current container node. In the case where a proxy plug-in is not provided as an image pulling tool, to implement the above operations, it is necessary to first intercept the traffic of the container runtime and process it, and then the container runtime will pull the image file to the target container node by itself. This means that the code of the container runtime needs to be modified. The present disclosure uses a proxy plug-in to replace the image pulling service of the container runtime itself. It only needs to perform the corresponding tool-specified operations in the configuration of the container runtime, which can reduce the intrusion into the container runtime code and provide a native image pulling method without the need for traffic interception and forwarding, thereby reducing the computing resource consumption of the current container node and helping to further speed up the image pulling speed.

[0024] In addition, each container node in the target container cluster provides services passively. In other words, whichever container node needs to pull the image file will complete the above process, avoiding wasting resources on other container nodes.

[0025] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute an improper limitation of the present disclosure.

[0027] Figure 1 The figure is a flowchart of a method for pulling an image of a container node according to an exemplary embodiment of the present disclosure.

[0028] Figure 2 It is a schematic diagram of the architecture of a cluster and an image repository according to a specific embodiment of the present disclosure.

[0029] Figure 3 It is a flowchart of a method for pulling an image of a container node according to a specific embodiment of the present disclosure.

[0030] Figure 4 is a block diagram of an image pulling apparatus for a container node according to an exemplary embodiment of the present disclosure.

[0031] Figure 5 is a block diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0032] In order to enable ordinary persons in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0033] It should be noted that the terms "first," "second," and the like in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the numbers used in this manner are interchangeable where appropriate so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The implementation methods described in the following examples do not represent all implementation methods consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with certain aspects of the present disclosure as detailed in the appended claims.

[0034] It should be noted that the phrase "at least one of the several items" in this disclosure includes three types of parallel situations: "any one of the several items", "a combination of any multiple of the several items", and "all of the several items". For example, "including at least one of A and B" includes the following three parallel situations: (1) including A; (2) including B; (3) including A and B. For another example, "performing at least one of step 1 and step 2" means the following three parallel situations: (1) performing step 1; (2) performing step 2; and (3) performing both step 1 and step 2.

[0035] First, let me introduce some technical terms in the field of container technology.

[0036] k8s cluster: Kubernetes (often abbreviated as k8s) is an open source container orchestration platform for automating the deployment, scaling, and management of containerized applications. A k8s cluster consists of a master node and multiple worker nodes. The master node is responsible for cluster management, including scheduling, maintaining, scaling, and updating applications. Worker nodes run application containers and report their status and resource usage. Kubernetes simplifies the deployment and management of containers by providing an abstraction layer, making it easier for developers and operations personnel to coordinate and manage distributed systems. The advantage of a k8s cluster is its high availability, scalability, and elasticity, which improves the reliability and performance of applications. It supports multiple cloud platforms and local data centers, providing flexible deployment methods.

[0037] Docker image: A Docker image is a read-only template for creating containers. It contains everything needed to run an application, including code, runtime environment, libraries, and dependencies. Each Docker image consists of a series of layered file systems, which together make up the final image. The layered structure of images makes them very efficient because different images can share the same layers, reducing storage space. Developers can start with a base image, add what they need, and generate a new image. The creation and distribution of images is very convenient, which allows applications to run on any platform that supports Docker. With Docker images, development and operations teams can ensure the consistency of applications in development, testing, and production environments.

[0038] OCI Standards: The Open Container Initiative (OCI) standards are an open source, community-driven project aimed at establishing an open, industry-standard container format and runtime specification. The OCI primarily consists of two specifications: the OCI Image Specification and the OCI Runtime Specification. The Image Specification defines the format and content of container images, allowing different container runtimes to use the same images. The Runtime Specification defines the container lifecycle management, including creating, starting, stopping, and deleting containers. By developing these standards, the OCI promotes interoperability and portability within the container ecosystem, preventing vendor lock-in. The adoption of OCI standards makes container technology more open and flexible, allowing developers to choose the container tools that best suit their needs without worrying about compatibility issues.

[0039] Docker Registry: Docker Registry is a system for storing and distributing Docker images. It can be a public image library, such as Docker Hub, or a private image library that enterprises can use to store and manage their own images. Docker Registry allows users to push (upload) and pull (download) images, and supports version management and access control. By using Docker Registry, development and operations teams can centrally manage images to ensure consistency and traceability. The existence of an image library makes the distribution and deployment of applications more convenient, and the same image can be easily used in different environments. Private Registries provide higher security and control, and are suitable for internal enterprise use. They can also be integrated with continuous integration (CI) and continuous delivery (CD) tools to achieve automated image management and deployment processes.

[0040] Hereinafter, an image pulling method, apparatus, electronic device, and storage medium for a container node according to exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0041] Figure 1 The figure is a flowchart of a method for pulling an image of a container node according to an exemplary embodiment of the present disclosure.

[0042] Reference Figure 1 In step 101, in response to a pull request for a target image file, a preferred node list for the current container node is obtained through a proxy plug-in preset in the current container node.

[0043] The preferred node list obtained in this step includes container nodes in the target container cluster whose communication speed with the current container node meets predetermined conditions. The predetermined conditions may include evaluation conditions for multiple communication speed-related indicators to indicate that the communication speed between the two container nodes is sufficient to meet the image pull speed requirements. The specific predetermined conditions can be configured as needed and are not limited in this disclosure.

[0044] As an example, the target container cluster is a cloud-edge cluster. In other words, the cluster includes both edge nodes and cloud-side nodes, which can adapt to the particularity of edge nodes and the complexity of the environment.

[0045] As an example, the target container cluster includes at least one container cluster. In the case of multiple container clusters, the networking function of the cluster CNI (Container Network Interface) plug-in can be used to achieve communication between multiple clusters, thereby realizing image sharing in cross-cluster scenarios, without being limited to image sharing between nodes in the same cluster.

[0046] In step 102, the proxy plug-in searches for a target container node storing the target image file from a preferred node list.

[0047] Optionally, step 102 includes: obtaining, via a proxy plug-in, descriptive information of image files stored by container nodes in a preferred node list from a container server, wherein the descriptive information stored by the container server is obtained from the proxy plug-in of each container node in the target container cluster; and searching, via the proxy plug-in, for a target container node storing the target image file from the preferred node list based on the descriptive information. By utilizing the image file descriptive information to record the image files stored by each container node, the image file storage status can be recorded and used with a relatively small amount of data. The descriptive information includes, but is not limited to, basic information such as the image file name and version number. Furthermore, by having the proxy plug-in in each container node aggregate the image file descriptive information of the corresponding node and uniformly sending it to the container server, reliable aggregation of the image file descriptive information can be achieved. Because the image file descriptive information is relatively small, the amount of data transmitted when acquiring this information from the container server is also relatively small, reducing the reliance on communication speed and the pressure on the image repository, thereby enabling efficient sharing of the image file descriptive information within the target container cluster. It should be understood that the image file descriptive information maintained by the container server is aggregated and reported by the proxy plug-in in each container node and is not metadata stored by the Docker registry in related art. As an example, the image file description information is a list recording the image files stored in the corresponding container node.

[0048] Of course, other methods may also be used to find the target container node, including but not limited to initiating a query to the container node in the preferred node list, that is, inquiring whether the corresponding container node stores the target image file, which is not limited in this disclosure.

[0049] In step 103, the target image file is pulled from the target container node through the proxy plug-in.

[0050] The proxy plug-in is configured as the image pulling tool for the container runtime of the current container node. It can replace the ImagePull service of the CRI (Container Runtime Interface), reduce the intrusion into the CRI code, and provide a native image pulling method without traffic interception and forwarding, thereby reducing node CPU resources and speeding up image acquisition.

[0051] Optionally, step 103 includes: pulling the target image file from the proxy plug-in in the target container node through the proxy plug-in. Taking into account that different container nodes do not have the permission to read each other's image files by default, corresponding read permission configuration is required before it can be implemented. The proxy plug-in is set in the container node and has the permission to read the image file stored in the container node, and there is no restriction on read permissions between proxy plug-ins. Based on this, by using the proxy plug-in of each container node as a medium, that is, using the proxy plug-in of the current container node, the target image file is pulled from the proxy plug-in of the target container node, without the need for complex read permission configuration for different nodes in the cluster, so that during the entire image pulling process, each node has the read permission of the container runtime image storage directory facing the remaining nodes, and the target image file stored in the target container node can be obtained through the synchronization mechanism (sync).

[0052] As an example, the proxy plug-in can also convert the target image file into BLOB format by layer, and then compress it to reduce the size of each layer and shorten the image pulling speed.

[0053] As an example, traffic between nodes may be encrypted, for example, including but not limited to encryption using SSL (Secure Sockets Layer) technology, to achieve security in inter-node communication and ensure consistency of transmission nodes.

[0054] According to the image pulling method of the container node of the exemplary embodiment of the present disclosure, by obtaining a preferred node list consisting of container nodes that meet predetermined conditions in the target container cluster for the current container node, and pulling the target image file required by the current container node from the container nodes in the list, the image pulling efficiency can be effectively improved, the dependence on the centralized image repository can be reduced, and the problem of slow image pulling in cross-domain and cross-regional edge computing scenarios can be effectively solved.

[0055] At the same time, all nodes (including edge nodes) in the existing Kubernetes cluster pull images independently. For example, if 100 nodes need to pull a 1Gb Docker image at the same time, the image repository server will be overloaded with 100Gbps. In a shared cloud environment with traffic-based billing, the traffic cost is 100 times that of pulling a single image. The present disclosure can reduce the data processing pressure on the image repository by redirecting traffic that should have been pulled from the image repository to container nodes in the preferred node list, effectively reducing the request traffic to the image repository and lowering the cost of pulling images.

[0056] Furthermore, the present disclosure also provides a special proxy plug-in to perform the above operations, and configures the proxy plug-in as an image pulling tool for the container runtime of the current container node. In the case where a proxy plug-in is not provided as an image pulling tool, to implement the above operations, it is necessary to first intercept the traffic of the container runtime and process it, and then the container runtime will pull the image file to the target container node by itself. This means that the code of the container runtime needs to be modified. The present disclosure uses a proxy plug-in to replace the image pulling service of the container runtime itself. It only needs to perform the corresponding tool-specified operations in the configuration of the container runtime, which can reduce the intrusion into the container runtime code and provide a native image pulling method without the need for traffic interception and forwarding, thereby reducing the computing resource consumption of the current container node and helping to further speed up the image pulling speed.

[0057] In addition, each container node in the target container cluster provides services passively. In other words, whichever container node needs to pull the image file will complete the above process, avoiding wasting resources on other container nodes.

[0058] Next, a method for pulling an image of a container node according to an exemplary embodiment of the present disclosure is further introduced.

[0059] Regarding the preferred node list obtained in step 101, the preferred node list is optionally determined by the proxy plug-in performing the following steps: detecting network quality indicators between multiple container nodes in the target container cluster and the current container node, and obtaining reference information of candidate container nodes, wherein the reference information includes at least one of the following: hardware resource data, network topology relationship, and node IP address; determining, from the multiple container nodes, container nodes whose network quality indicators meet preset network conditions and whose reference information meets preset reference conditions as candidate container nodes; determining scores for the candidate container nodes based on the network quality indicators and the reference information; and screening container nodes from the candidate container nodes based on the scores and adding them to the preferred node list. By first screening candidate container nodes based on the network quality indicators and reference information, then scoring the candidate container nodes based on the two, and then screening container nodes based on the scores, a two-stage node screening process can be achieved, which not only meets the screening requirements but also reduces the amount of data processing and improves processing efficiency. As an example, the network quality indicators may include packet loss rate and delay, and the corresponding preset network conditions may include a packet loss rate less than a packet loss rate threshold and a delay less than a delay threshold. Regarding reference information, hardware resource data can reflect the data processing capabilities of the corresponding container node, and can also help improve the image pulling speed. The network topology relationship can describe the ownership distance relationship between different nodes in the cluster, making it easier to give priority to nodes that are closer to the current container node, which helps improve the image pulling speed. The node IP address is a deeper relationship based on the network topology relationship. Specifically, even in the same computer room, the communication speed between devices belonging to the same switch will be faster than the communication speed between devices belonging to different switches. This makes it easier to give priority to nodes on devices that belong to the same switch as the current container node, which helps further improve the image pulling speed. In general, using the above method to determine the preferred node list can help adjacent and nearby nodes share image files with each other, and solve the problems of slow image pulling speed and abnormal image pulling due to network problems.

[0060] As an example, the preferred node list is maintained by the aforementioned proxy plug-in in each container node. The proxy plug-in can act as a Kubernetes client, obtaining and caching the hardware resource status of all nodes through the Kubernetes API server. When each proxy plug-in starts, it can first perform initialization work, pre-exploring the network quality indicators and reference information of other nodes, and determining an initial preferred node list. It can also obtain the image file description information of each container node in this list accordingly. When the target container node needs to be determined, it can directly query the local cache and use it. Furthermore, the proxy plug-in needs to update the optimized node list. This can be done regularly or in response to pull requests for the target image file. Of course, both methods can be used simultaneously, and other reasonable methods can also be used. For example, the proxy plug-in can use the Kubernetes Watch mechanism to quickly obtain status changes of cluster nodes, improving the timeliness of updates. Of course, other methods can also be used to obtain information. When updating the preferred node list, for example, incremental modifications can be performed to reduce the impact on each node and improve maintenance efficiency.

[0061] As an example, the number of container nodes in the preferred node list is greater than or equal to 0 and less than or equal to a first preset number, where the first preset number is a set ratio of the total number of nodes in the target container cluster, and the set ratio ranges from 5% to 15%, including but not limited to 8%, 10%, and 12%. By controlling the number of nodes included in the preferred node list to within the set ratio of the total number of nodes, high-quality nodes can be selected centrally, reducing data storage pressure and effectively improving image pull speed.

[0062] Further optionally, the container nodes recorded in the preferred node list are arranged in descending order according to the communication speed between them and the current container node. For the embodiment described above of using scores to determine the container nodes in the preferred node list, the nodes are arranged in descending order according to the scores, thereby utilizing sorting to reflect the communication speed.

[0063] Accordingly, when executing step 102, the preferred node list can be traversed in order to determine whether the container nodes in the list store the target image file, that is, to determine whether the container nodes in the list are target container nodes. As an example, only one target container node can be determined, that is, once a target container node is determined, the traversal stops. Alternatively, it is not limited to one target container node, but multiple target container nodes can be determined. For example, all nodes in the list that can be used as target container nodes can be determined. Alternatively, a second preset number can be set, and only target container nodes not exceeding the second preset number can be determined. Then, when the second preset number of target container nodes is determined, the traversal can be stopped. Of course, after traversing all container nodes in the list, the traversal will naturally stop, and target container nodes less than or equal to the second preset number will be obtained. Of course, these two methods can also be combined to treat the target image file differently based on the cache status of the target image file in the cluster. If the base image is widely cached, multiple target container nodes can be determined. If the base image is not widely cached, such as a newly deployed custom image, only one target container node can be determined. It should be understood that, for an embodiment in which the preferred node list is not sorted according to the communication speed, the target container node can also be determined by traversing the preferred node list.

[0064] For the above situation where only one target container node is determined, step 103 can directly pull the target image file from the target container node.

[0065] For the above-mentioned situation where multiple target container nodes are allowed to be determined, step 103 can first further screen these multiple target container nodes in combination with other reasonable information to obtain a final container node, and pull the target image file from this container node, or simultaneously pull the target image file from these multiple target container nodes. For the former, it is essentially the same as the situation described in the previous paragraph. For the latter, specifically, the hierarchical storage structure of the image file can be used to pull different image layer files of the target image file from different target container nodes. For example, including but not limited to evenly distributing according to the number of image layer files, preferentially allocating larger image layer files to target container nodes with faster communication speeds, etc., to achieve parallel pulling of different image layer files, and at this time, the traffic pressure is also reduced from the input and output pressure of a single node to about 1 / N (N is the number of target container nodes), which can achieve traffic diversion.

[0066] If the target container node is not determined, that is, the proxy plug-in does not find the container node storing the target image file in the preferred node list, the target image file can be pulled from the image warehouse.

[0067] In other words, the performance of the image pulling method of the exemplary embodiment of the present disclosure can be divided into two typical scenarios. One is that the target image file can be pulled from multiple target container nodes. For example, when the base image is widely cached, zero access to the image repository can be achieved, and it is completed entirely through inter-node transmission. The other is that the required target image file is not stored in any container node, such as a newly deployed custom image file, in which case it still needs to be fully pulled from the public network image repository.

[0068] Of course, you can also combine the target container node and the image repository to pull different image layer files from the target container node and the image repository in parallel.

[0069] In addition, the image layer files belonging to the target image file stored in the current container node can be determined as local image layer files, and the image layer files other than the local image layer files in the target image file can be determined as differential image layer files. The differential image layer files are pulled from the target container node through the proxy plug-in, thereby utilizing the hierarchical storage structure of the Docker image to achieve deduplication transmission, that is, the existing layers directly reuse the local storage and only transmit the differential layers. For the differential layers, the above-mentioned multiple embodiments can be used for single-node pulling or parallel pulling.

[0070] After completing the pulling of the target image file, you can also perform a security check on the pulled file, and then save the safe target image file that passes the check to the current container node.

[0071] Optionally, regarding the preservation of files, the image pulling method according to the exemplary embodiment of the present disclosure further includes: using a proxy plug-in to save the target image file in the prescribed format of the container runtime of the current container node when the container runtime of the target container node is of a different type from the container runtime of the current container node. By designing the proxy plug-in with the ability to convert the target image file format for different types of container runtimes, the selection of the target container node can be unrestricted by the type of its container runtime, achieving compatibility with multiple container runtimes without relying on interfaces, thereby sharing images between different container runtimes. For example, the master node uses CRIO (Container Runtime Interface – OCI, Container Runtime Interface - Open Container Initiative) and the edge node uses containerd. Then, through dynamic adaptation through the proxy plug-in, the image is pulled from CRIO and stored in the containerd of the current node, and saved in the prescribed format of CRIO, that is, the local image metadata database ( / var / lib / containers / storage / db.sql) of containerd is rewritten.

[0072] Next, combine Figure 2 and Figure 3 A method for pulling an image of a container node according to a specific embodiment of the present disclosure is introduced.

[0073] In this specific embodiment, Figure 2 As shown, the target container cluster is a cloud-edge cluster. The diagram shows two components: the image repository primarily provides image pull services. The master, worker, and edge nodes in the diagram below all pull images from the image repository. The master and worker nodes comprise the cloud-side portion of edge computing, typically located in high-quality data centers with good network environments. The edge nodes, comprising the edge nodes, are typically located in data centers, factories, vehicles, and other locations with poor network environments.

[0074] Combine first Figure 2 A brief explanation of the image pulling strategy of related technologies: Generally, all nodes in the cluster will pull images from the image warehouse. For example, master-1 may pull images from docker.io, worker-1 may pull images from quay.io, and each edge may pull images from a private warehouse. Figure 2 It can be seen that nodes and image repositories span regions and countries, so there will be negative impacts such as network timeouts, packet loss, and slow speeds during the image pulling process.

[0075] The specific embodiment of the present disclosure maintains a list of preferred nodes at each node. The nodes in the list are selected by sorting in descending order through node filtering and scoring mechanisms, selecting 10% of the total number of nodes and adding them to the list, ensuring that the number of nodes available for selection in the list is greater than or equal to 0 and less than or equal to 10% of the total number of nodes.

[0076] Regarding the node filtering and scoring mechanism, specifically, eight ICMP (Internet Control Message Protocol) packets specifically used to detect network quality are sent from the current container node to each node in the cluster. The packet loss rate and round-trip delay are calculated, and nodes with a packet loss rate greater than 75% and a round-trip delay greater than 200ms are filtered out. For each correct packet, the node receives 10 points.

[0077] Calculate the node CPU and memory pressures obtained in the previous step and filter out nodes with less than 30% CPU remaining and less than 2GB of memory remaining. Add 1 point for every GB of memory remaining and 1 point for every 10% of CPU remaining. The remaining nodes are considered candidate container nodes.

[0078] For each candidate container node, the network topology of the node is retrieved through the Kubernetes API. Nodes in the same domain as the current container node receive 8 points, while nodes in different domains receive no points. The IP address of the candidate container node is retrieved. Nodes in the same subnet as the current container node receive 12 points, while nodes in different subnets receive no points.

[0079] After obtaining the preferred node list, when a node needs to pull an image from the public network warehouse, it first queries the nodes in its preferred node list. If the required image already exists in the node in the list, it is obtained from the node in the list. If the required image does not exist in any node in the list, it is pulled from the image warehouse.

[0080] like Figure 3 As shown, the main workflow of the proxy plug-in in the current node is to update the preferred node list in response to receiving a request to pull the target image, and then ask each node one by one whether the target image exists starting from the first node in the preferred node list, until the last node in the list. If the node in the list has the target image, the next step is executed, otherwise the target image is pulled from the image warehouse. When executing the next step, the target image stored by the node in the list is copied to the temporary directory of the current node, and the image warehouse is queried for information about the target image, including the sha256 value of each layer of the target image, and a security check is performed accordingly, that is, whether the corresponding information of the copied target image is consistent with that queried from the image warehouse, thereby ensuring the legitimacy, security, and integrity of the target image obtained from other nodes, and the request traffic to the image warehouse during the entire process is at the KB level, without the need to pull the complete image, which can reduce the bandwidth pressure on the image warehouse and speed up the pulling of the image. If the security check passes, the target image in the temporary directory is copied to the container runtime image storage directory, and the container runtime image directory database is updated, and the container is run, otherwise the target image is pulled from the image warehouse and the container is run.

[0081] Figure 4 is a block diagram of an image pulling device for a container node according to an exemplary embodiment of the present disclosure. Figure 4 The device includes an acquisition unit 401, a search unit 402 and a first pulling unit 403.

[0082] The acquisition unit 401 can respond to a pull request for the target image file and obtain a preferred node list for the current container node through a proxy plug-in preset in the current container node, wherein the preferred node list includes container nodes in the target container cluster whose communication speed with the current container node meets predetermined conditions.

[0083] The search unit 402 may search for a target container node storing a target image file from the preferred node list through the proxy plug-in.

[0084] The first pulling unit 403 may pull the target image file from the target container node through the proxy plug-in.

[0085] The proxy plugin is configured as the image puller for the container runtime of the current container node.

[0086] Optionally, the first pulling unit 403 may also pull the target image file from a proxy plug-in in the target container node through the proxy plug-in.

[0087] Optionally, the search unit 402 may also: obtain, from the container server through a proxy plug-in, description information of the image file stored in the container node in the preferred node list, wherein the description information stored in the container server is obtained from the proxy plug-in of each container node in the target container cluster; and search, through the proxy plug-in, for the target container node storing the target image file from the preferred node list based on the description information.

[0088] Optionally, the image pulling device according to the embodiment of the present disclosure also includes a storage unit (not shown in the figure), which can save the target image file in the specified format of the container runtime of the current container node through the proxy plug-in when the container runtime of the target container node is of a different type from the container runtime of the current container node.

[0089] Optionally, the preferred node list is determined by the proxy plug-in performing the following steps: detecting network quality indicators between multiple container nodes in the target container cluster and the current container node, and obtaining reference information of candidate container nodes, wherein the reference information includes at least one of the following: hardware resource data, network topology relationship, node IP address; determining, from multiple container nodes, container nodes whose network quality indicators meet preset network conditions and whose reference information meets preset reference conditions as candidate container nodes; determining scores of candidate container nodes based on the network quality indicators and the reference information; and screening container nodes from the candidate container nodes based on the scores, and adding them to the preferred node list.

[0090] Optionally, the image pulling device according to an embodiment of the present disclosure further includes a second pulling unit (not shown in the figure), which can pull the target image file from the image repository when the proxy plug-in does not find the container node storing the target image file in the preferred node list.

[0091] According to an embodiment of the present disclosure, an electronic device may be provided. Figure 5It is a block diagram of an electronic device 500 according to an embodiment of the present disclosure, which includes at least one memory 501 and at least one processor 502. The at least one memory stores a computer-executable instruction set 5011 and an operating system 5012. When the computer-executable instruction set 5011 is executed by the at least one processor 502, the image pulling method of the container node according to the embodiment of the present disclosure is executed.

[0092] As an example, electronic device 500 may be a PC, tablet device, personal digital assistant, smartphone, or other device capable of executing the aforementioned set of instructions. Here, electronic device 500 is not necessarily a single electronic device, but may also be any collection of devices or circuits capable of executing the aforementioned instructions (or instruction set) individually or in combination. Electronic device 500 may also be part of an integrated control system or system manager, or may be configured as a portable electronic device that interfaces with local or remote devices (e.g., via wireless transmission).

[0093] In electronic device 500, processor 502 may include a central processing unit (CPU), a graphics processing unit (GPU), a programmable logic device, a dedicated processor system, a microcontroller, or a microprocessor. By way of example and not limitation, processor 502 may also include an analog processor, a digital processor, a microprocessor, a multi-core processor, a processor array, a network processor, etc.

[0094] The processor 502 can execute instructions or codes stored in the memory, wherein the memory 501 can also store data. Instructions and data can also be sent and received over the network via the network interface device, wherein the network interface device can use any known transmission protocol.

[0095] Memory 501 may be integrated with processor 502, for example, by placing RAM or flash memory within an integrated circuit microprocessor or the like. Furthermore, memory 501 may comprise a separate device, such as an external disk drive, a storage array, or any other storage device usable by a database system. Memory 501 and processor 502 may be operatively coupled or may communicate with each other, for example, via an I / O port, a network connection, or the like, such that processor 502 can access files stored in memory 501.

[0096] In addition, the electronic device 500 may further include a video display (such as a liquid crystal display) and a user interaction interface (such as a keyboard, a mouse, a touch input device, etc.) All components of the electronic device may be connected to each other via a bus and / or a network.

[0097] According to an embodiment of the present disclosure, a computer-readable storage medium may also be provided, wherein, when the instructions in the computer-readable storage medium are executed by at least one processor, the at least one processor is prompted to execute the image pulling method of the container node of the embodiment of the present disclosure. Examples of computer-readable storage media here include: read-only memory (ROM), random access programmable read-only memory (PROM), electrically erasable programmable read-only memory (EEPROM), random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), flash memory, non-volatile memory, CD-ROM, CD-R, CD+R, CD-RW, CD+RW, DVD-ROM, DVD-R, DVD+R, DVD-RW, DVD+RW, DVD-RAM, BD-ROM, BD-R, BD-R LTH, BD-RE, Blu-ray or optical disk storage, hard disk drive (HDD), solid state drive (SSD), card storage (such as a multimedia card, secure digital (SD) card or extreme digital (XD) card), magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid state disk and any other device configured to store a computer program and any associated data, data files and data structures in a non-transitory manner and provide the computer program and any associated data, data files and data structures to a processor or computer so that the processor or computer can execute the computer program. The computer program in the above-mentioned computer-readable storage medium can be executed in an environment deployed in a computer device such as a client, a host, an agent device, a server, etc. In addition, in one example, the computer program and any associated data, data files and data structures are distributed on a networked computer system so that the computer program and any associated data, data files and data structures are stored, accessed and executed in a distributed manner by one or more processors or computers.

[0098] According to an embodiment of the present disclosure, a computer program product is provided, including computer instructions, which, when executed by a processor, implement the image pulling method for a container node according to an embodiment of the present disclosure.

[0099] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

[0100] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A method for pulling an image of a container node, characterized in that: include: In response to a pull request for a target image file, obtaining, through a proxy plug-in preset in the current container node, a preferred node list for the current container node, wherein the preferred node list includes container nodes in the target container cluster whose communication speed with the current container node meets a predetermined condition; Searching, by the proxy plug-in, for a target container node storing the target image file from the preferred node list; Pull the target image file from the target container node through the proxy plug-in; The proxy plug-in is configured as an image pulling tool during the container runtime of the current container node.

2. The image pulling method according to claim 1, wherein: Pulling the target image file from the target container node through the proxy plug-in includes: The target image file is pulled from the proxy plug-in in the target container node through the proxy plug-in.

3. The image pulling method according to claim 1, wherein: The searching, by the proxy plug-in, for a target container node storing the target image file from the preferred node list includes: Obtaining, from a container server through the proxy plug-in, description information of the image files stored by the container nodes in the preferred node list, wherein the description information stored by the container server is obtained from the proxy plug-in of each container node in the target container cluster; The proxy plug-in searches for a target container node storing the target image file from the preferred node list according to the description information.

4. The image pulling method according to claim 1, wherein: Also includes: When the container runtime of the target container node is different from the container runtime of the current container node, the target image file is saved in a format specified by the container runtime of the current container node through the proxy plug-in.

5. The image pulling method according to claim 1, wherein: The preferred node list is determined by the proxy plug-in performing the following steps: Detect network quality indicators between multiple container nodes in the target container cluster and the current container node, and obtain reference information of the candidate container node, wherein the reference information includes at least one of the following: hardware resource data, network topology relationship, and node IP address; Determine, from the multiple container nodes, a container node whose network quality indicator meets a preset network condition and whose reference information meets a preset reference condition as a candidate container node; Determining a score for the candidate container node based on the network quality indicator and the reference information; Container nodes are screened from the candidate container nodes according to the scores, and added to the preferred node list.

6. The image pulling method according to any one of claims 1 to 5, wherein: Also includes: When no container node storing the target image file is found in the preferred node list through the proxy plug-in, the target image file is pulled from the image warehouse.

7. A container node image pulling device, characterized in that: include: an acquiring unit configured to, in response to a pull request for a target image file, acquire, through a proxy plug-in preset in the current container node, a preferred node list for the current container node, wherein the preferred node list includes container nodes in the target container cluster whose communication speed with the current container node meets a predetermined condition; a search unit configured to search, through the proxy plug-in, for a target container node storing the target image file from the preferred node list; A first pulling unit is configured to pull the target image file from the target container node through the proxy plug-in; The proxy plug-in is configured as an image pulling tool during the container runtime of the current container node.

8. An electronic device, characterized in that: include: at least one processor; at least one memory storing computer-executable instructions, When the computer-executable instructions are executed by the at least one processor, they prompt the at least one processor to execute the image pulling method for a container node according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that When the instructions in the computer-readable storage medium are executed by at least one processor, the instructions cause the at least one processor to execute the image pulling method for a container node according to any one of claims 1 to 6.

10. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by at least one processor, the computer instructions cause the at least one processor to execute the image pulling method for a container node according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • P2P network node selection method and device, equipment and storage medium

    CN113765970A

  • Machine learning container mirror image downloading system and method for Internet of Things

    CN115543538A

  • Method and system for accelerating mirror image loading of AIGC application container in edge scene

    CN119211210A

  • Container mirror image acquisition method and device, equipment, medium and program product

    CN119415219A