Communication method and device

By introducing virtual and proxy edge nodes, the problem of inaccurate management of container orchestration systems in one-way network environments is solved, and efficient and reliable management and status monitoring of edge devices are achieved.

CN120602483APending Publication Date: 2025-09-05BEIJING PACTERA JINXIN TECH LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202510912748.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In a one-way network communication environment, existing container orchestration systems cannot effectively manage edge devices, resulting in inaccurate and unreliable management.

Method used

The introduction of virtual edge nodes and proxy edge nodes ensures that container management messages are accurately parsed and executed on edge devices through protocol conversion and structured parsing.

Benefits of technology

It achieves accurate management of edge devices in a one-way network environment, improves the availability and robustness of the system, and supports container status monitoring and reliable return of log data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602483A_ABST
    Figure CN120602483A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device, the communication method and device are applied to agent edge nodes, the agent edge nodes are arranged between virtual edge nodes and a target engine, the target engine is used for managing a local container of an entity edge node agented by the agent edge nodes, and the method comprises the following steps: receiving a container management message sent by the virtual edge nodes; performing structured analysis on the container management message to obtain the message content and the message type of the container management message; according to the message content and the message type, calling a target engine to execute a target container management strategy on a target container instance in a local container; therefore, efficient issuing and automatic execution of the container management message from the central cloud to the edge device are realized, and the management accuracy and effectiveness of the entity edge node in a limited network environment are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to a communication method and device. Background Art

[0002] With the continuous development of edge computing, more and more computing tasks are being offloaded to edge devices (physical edge nodes) to improve system responsiveness, reduce network bandwidth consumption, and achieve local autonomy and efficient operation. In this context, container orchestration systems, with their flexible resource scheduling capabilities and efficient container management mechanisms, have been widely used in cloud-edge collaborative architectures. Therefore, effectively managing container instances in container orchestration systems in such edge deployment environments has become a key issue in ensuring stable operation of edge devices and efficient resource utilization. Summary of the Invention

[0003] The present disclosure provides a communication method and apparatus to at least partially address one of the technical problems in the related art. The technical solution of the present disclosure is as follows:

[0004] According to a first aspect of an embodiment of the present disclosure, a communication method is provided, which is applied to a proxy edge node, wherein the proxy edge node is arranged between a virtual edge node and a target engine, and the target engine is used to manage a local container of a physical edge node proxied by the proxy edge node. The method includes: receiving a container management message sent by the virtual edge node; performing structured parsing on the container management message to obtain the message content and message type of the container management message; and calling the target engine to execute a target container management policy on a target container instance in the local container based on the message content and the message type.

[0005] According to a second aspect of an embodiment of the present disclosure, a communication device is provided, which is applied to a proxy edge node. The proxy edge node is arranged between a virtual edge node and a target engine. The target engine is used to manage a local container of a physical edge node proxied by the proxy edge node. The device includes: a receiving module for receiving a container management message sent by the virtual edge node; a parsing module for performing structured parsing on the container management message to obtain the message content and message type of the container management message; and a processing module for calling the target engine to execute a target container management policy on a target container instance in the local container based on the message content and the message type.

[0006] According to a third aspect of an embodiment of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the communication method as described in the embodiment of the first aspect of the present disclosure.

[0007] According to a fourth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided. When instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the communication method as described in the embodiment of the first aspect of the present disclosure.

[0008] According to a fifth aspect of an embodiment of the present disclosure, a computer program product is provided, comprising: a computer program, wherein when the computer program is executed by a processor, the communication method as described in the embodiment of the first aspect of the present disclosure is implemented.

[0009] The technical solutions provided by the embodiments of the present disclosure bring at least the following beneficial effects:

[0010] In this technical solution, by setting up virtual edge nodes and proxy edge nodes in the system, the proxy edge nodes can reliably receive container management messages from the central cloud in a one-way network scenario by receiving container management messages sent by the virtual edge nodes. Furthermore, the proxy edge nodes perform structured parsing on the received container management messages, extracting the message content and message type from them, so that even in the absence of real-time interaction capabilities, the edge devices can accurately understand the management intentions and specific operation parameters of the central cloud, thereby effectively ensuring the accurate parsing and accurate execution of container management messages. Finally, based on the parsed message content and message type, the proxy edge node calls the local container engine and executes the corresponding container management policy on the target container instance, thereby realizing the complete mapping and automatic execution of container operation instructions from the central cloud to the edge device, significantly improving the management accuracy of the physical edge node in a restricted network environment. The system improves the safety and effectiveness of the edge node and the network environment, and realizes the remote perception of the running status of edge containers and nodes based on the virtual edge node and the proxy edge node, thereby realizing the reliable transmission and centralized management of container status, monitoring data or log data in the restricted environment where the edge device cannot actively initiate a connection and only supports receiving instructions in the restricted environment of one-way network communication.

[0011] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute an improper limitation of the present disclosure.

[0013] Figure 1 is a flow chart of a communication method according to the first embodiment of the present disclosure;

[0014] Figure 2 is a schematic diagram of the container orchestration system structure shown in an embodiment of the present disclosure;

[0015] Figure 3 is a flow chart of a communication method according to the second embodiment of the present disclosure;

[0016] Figure 4 is a flow chart of a communication method according to the third embodiment of the present disclosure;

[0017] Figure 5 is a flow chart of a communication method according to a fourth embodiment of the present disclosure;

[0018] Figure 6 It is a schematic diagram of the principle of a communication method shown in an embodiment of the present disclosure;

[0019] Figure 7 is a flow chart of a communication method according to a fifth embodiment of the present disclosure;

[0020] Figure 8 is a flow chart of a communication method according to a sixth embodiment of the present disclosure;

[0021] Figure 9 is a schematic diagram of another communication method shown in an embodiment of the present disclosure;

[0022] Figure 10 is a schematic structural diagram of a communication device shown in the seventh embodiment of the present disclosure;

[0023] Figure 11 It is a schematic structural diagram of an electronic device shown in an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0024] In order to enable ordinary persons in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0025] It should be noted that the terms "first," "second," and the like in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the numbers used in this manner are interchangeable where appropriate so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure as detailed in the appended claims.

[0026] It should be noted that in the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision and disclosure of user personal information are all carried out with the user's consent, and are in compliance with relevant laws and regulations and do not violate public order and good morals.

[0027] In related technologies, the architecture of the container orchestration system relies on establishing stable two-way network communication between each node in the cluster and the central cloud. However, in some special edge computing scenarios, due to network security, physical isolation or policy restrictions, the network environment where the edge device (physical edge node) is located may be a one-way network communication environment, that is, only data is allowed to be sent from the central cloud to the edge device, and the edge device cannot initiate communication with the central cloud. The container orchestration system will not be able to operate normally under this one-way communication constraint, and it will not be able to effectively manage the edge device. Therefore, how to achieve effective management of edge devices under the one-way communication constraint has become an urgent problem to be solved.

[0028] The communication method and apparatus according to the embodiments of the present disclosure will be described below with reference to the accompanying drawings.

[0029] Figure 1 It is a flowchart of the communication method shown in the first embodiment of the present disclosure.

[0030] It should be noted that the embodiment of the present disclosure is applied to a proxy edge node, which is arranged between a virtual edge node and a target engine. The target engine is used to manage the local container of the physical edge node proxied by the proxy edge node.

[0031] It should be noted that since different physical edge nodes may run different types of container engines (such as Docker Engine or containerd), the communication protocols they support may also differ from the standard protocols on the central cloud side, which may cause the container management messages issued by the central cloud to be unable to be directly recognized and executed by the physical edge nodes. In order to ensure that the container management instructions can be reliably transmitted from the central cloud to the physical edge nodes and be executed correctly, a virtual edge node can be introduced as an intermediary between the central cloud and the edge devices; the virtual edge node is responsible for implementing protocol conversion and message forwarding functions, adapting the container management messages of the central cloud to a format recognizable by the physical edge nodes, and forwarding them to the corresponding edge nodes

[0032] In addition, an agent edge node can be set up between the virtual edge node and the local container engine (i.e., the target engine). The agent edge node further ensures that the container management messages from the central cloud to the edge device can be accurately understood and efficiently executed by performing structured parsing and local execution of the container management messages, thereby improving the compatibility, stability, and manageability of the entire system.

[0033] For example, Figure 2 As shown, the virtual edge node is located on the central cloud side. The central cloud sends container management messages through the virtual edge node. The proxy edge node is deployed on the edge side, between the virtual edge node and the target engine that actually runs the container instance. It is used to receive the container management messages sent by the central cloud through the virtual edge node, and is used for the transmission, parsing and execution of container management messages. The target engine is deployed on the physical edge node and is responsible for the creation, destruction, monitoring and other operations of specific container instances; the physical edge node is a physical device that carries local container operation tasks and may be in a restricted network environment (such as one-way communication).

[0034] like Figure 1 As shown, the communication method includes the following steps:

[0035] Step 101: Receive a container management message sent by a virtual edge node.

[0036] To enable message delivery from the central cloud to edge devices, in the disclosed embodiment, the proxy edge node receives container management messages forwarded by the virtual edge node. These messages may include, but are not limited to, control instructions for controlling the container lifecycle, messages for distributing container images, request messages for triggering monitoring data collection, and log collection requests for obtaining container logs.

[0037] Step 102: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0038] In order to enable the proxy edge node to correctly call the target engine to execute the container management operation indicated by the container management message, in the embodiment of the present disclosure, the container management message is structured and parsed, that is, the received message (such as JSON, Protobuf, etc.) is parsed into a data structure that can be recognized by the program, and the corresponding message content and message type are extracted; wherein, the message type is used to identify the management operation category corresponding to the container management message, such as "image distribution", "container control", "monitoring data collection" or "log collection", and the message content includes specific parameters (such as container name, image address, port configuration, etc.).

[0039] Step 103: Based on the message content and message type, the target engine is called to execute the target container management policy on the target container instance in the local container.

[0040] Furthermore, based on the management operation category and specific content in the received container management message, the proxy node can call the local container engine (ie, the target engine, such as Docker) to perform corresponding management operations on the specific container instance.

[0041] In summary, by setting up virtual edge nodes and proxy edge nodes in the system, the proxy edge nodes can reliably receive container management messages from the central cloud in a one-way network scenario by receiving container management messages sent by the virtual edge nodes. Furthermore, the proxy edge nodes perform structured parsing on the received container management messages and extract the message content and message type from them, so that even in the absence of real-time interaction capabilities, the edge devices can accurately understand the management intentions and specific operation parameters of the central cloud, thereby effectively ensuring the accurate parsing and accurate execution of container management messages. Finally, based on the parsed message content and message type, the proxy edge node calls the local target container engine and executes the corresponding container management policy on the target container instance, thereby realizing the complete mapping and automatic execution of container operation instructions from the central cloud to the edge device, significantly improving the management accuracy and effectiveness of the physical edge node in a restricted network environment.

[0042] In order to clearly illustrate how the target engine is called to execute the target container management policy on the target container instance in the local container according to the message content and message type in the above embodiment, the present disclosure proposes another communication method.

[0043] Figure 3 It is a flow chart of the communication method shown in the second embodiment of the present disclosure. It should be noted that the embodiment of the present disclosure is applied to a proxy edge node.

[0044] like Figure 3 As shown, the communication method includes the following steps:

[0045] Step 301: Receive a container management message sent by a virtual edge node.

[0046] Step 302: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0047] Step 303: Determine the target container instance according to the container identification information in the message content and at least one container instance in the local container.

[0048] In order to improve the accuracy of container management, as a possible implementation method, the proxy edge node can search for the container instance of the local container based on the container identification information carried in the received container management message. If there is a container instance in the local container that matches the container identification information carried in the container management message, the container instance matching the container identification information will be used as the target container instance; if there is no container instance in the local container that matches the container identification information carried in the container management message, it means that it may be necessary to create a target container instance of the container identification information in the local container.

[0049] Step 304: Invoke the target engine to execute the target container management policy adapted to the message type on the target container instance.

[0050] To achieve precise management of container instances, the proxy edge node determines the adapted target container management policy based on the message type of the container management message, and calls the target engine to execute the policy, thereby ensuring accurate control and orderly execution of container operations on edge devices.

[0051] It should be noted that the execution process of steps 301 to 302 can be implemented in any of the embodiments of the present disclosure, and the embodiments of the present disclosure do not limit this and will not be described in detail.

[0052] In summary, by parsing the container identification information in the container management message and searching for the matching container instance in the local container, the target container is accurately located; then, the corresponding target container management policy is called according to the message type, and the local container engine is driven to perform corresponding operations. This not only improves the response accuracy and execution efficiency of the physical edge node to the central cloud instructions, but also supports restricted environments such as one-way communication or unstable network, so that the proxy edge node can independently complete the parsing and execution of container management messages without relying on real-time interaction with the central cloud, thereby significantly enhancing the availability and robustness of the system.

[0053] In order to clearly illustrate how to call the target engine in the above embodiment and execute the target container management policy adapted to the message type on the target container instance, the present disclosure proposes another communication method.

[0054] Figure 4 It is a flow chart of the communication method shown in the third embodiment of the present disclosure. It should be noted that the embodiment of the present disclosure is applied to a proxy edge node.

[0055] like Figure 4 As shown, the communication method includes the following steps:

[0056] Step 401: Receive a container management message sent by a virtual edge node.

[0057] Step 402: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0058] Step 403: Determine the target container instance according to the container identification information in the message content and at least one container instance in the local container.

[0059] Step 404: When the message type includes a container control instruction, identify the container control type from the message content.

[0060] In order to improve the accuracy of container management, as a possible implementation method, when the message type of the container management message is a container control instruction, the proxy edge node can identify the specific container control type (such as start, stop, restart, etc.) from the message content.

[0061] Step 405: Based on the container control type, the target engine is called to perform a lifecycle control operation adapted to the container control type on the target container instance.

[0062] Then, based on the identified container control type, the proxy edge node calls the locally running target engine and performs lifecycle control operations (start container, stop container, restart container, pause container) that match the control type on the identified target container instance, thereby achieving remote management and precise control of the container status on the edge device. It should be noted that when the container control type is to create a container, the target container instance matching the container identification information in the message content is directly created in the local container.

[0063] In addition, it should be noted that in order to achieve real-time monitoring of the running status of container instances, after completing its lifecycle management, the central cloud can send container status query requests through the virtual edge node to obtain the current status information of the target container instance on the edge device, thereby improving the system's observability and operation and maintenance efficiency.

[0064] As an example, a container status query request sent by a virtual edge node is received; the container status query request is responded to, status information of a target container instance is obtained, and a container status query response is generated according to the status information; and the container status query response is sent to the virtual edge node.

[0065] That is to say, the proxy edge node receives the container status query request sent by the virtual edge node, responds to the request, calls the local container engine to obtain the running status information of the target container instance, and generates a structured container status query response based on the obtained status information; then, the proxy edge node sends the response back to the virtual edge node, and the virtual edge node forwards the response to the central cloud, thereby realizing remote monitoring and centralized management of the edge container status. As a result, real-time perception and centralized management of the edge container status are realized in one-way communication or restricted network environments, which improves the observability and controllability of the system in one-way communication or restricted network environments, and at the same time enhances the collaboration between the central cloud and edge devices.

[0066] It should be noted that the execution process of steps 401 to 403 can be implemented in any of the embodiments of the present disclosure, and the embodiments of the present disclosure do not limit this and will not be described in detail.

[0067] In summary, after receiving a container control message, the specific container control type is identified from the message content, and the target container engine is called according to the container control type to perform the corresponding lifecycle control operation on the target container instance. This achieves accurate mapping of container control instructions and local execution actions, effectively ensuring the security, accuracy and execution efficiency of container management operations.

[0068] In order to clearly illustrate how to call the target engine in the above embodiment and execute the target container management policy adapted to the message type on the target container instance, the present disclosure proposes another communication method.

[0069] Figure 5 It is a flow chart of a communication method according to the fourth embodiment of the present disclosure. It should be noted that the embodiment of the present disclosure is applied to a proxy edge node.

[0070] like Figure 5 As shown, the communication method includes the following steps:

[0071] Step 501: Receive a container management message sent by a virtual edge node.

[0072] Step 502: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0073] Step 503: Determine the target container instance according to the container identification information in the message content and at least one container instance in the local container.

[0074] Step 504: When the message type includes image distribution, extract the image resource in the message content.

[0075] The image resource includes the target container image and the image signature of the target container image.

[0076] In an embodiment of the present disclosure, when the message type of the container management message is an image distribution instruction, the proxy edge node can extract the complete image resource from the message content; wherein the image resource not only includes the target container image file, but also includes an image signature for verifying its integrity and source credibility.

[0077] It should be noted that the image resources in the virtual edge node are generated using the following steps:

[0078] (1) in response to the target container image being created, performing vulnerability detection on the target container image to obtain a vulnerability detection result of the target container image;

[0079] In an embodiment of the present disclosure, after the target container image is built, the virtual edge node performs a security check on the target container image. For example, a vulnerability detection tool is used to scan the software packages, dependent libraries, base images, etc. in the target container image to obtain vulnerability detection results; wherein, the vulnerability detection results may include but are not limited to: whether there are known vulnerabilities, the severity level of the vulnerabilities, etc.

[0080] (2) in response to the vulnerability detection result indicating that the target container image does not contain a vulnerability, digitally signing the target container image to obtain an image signature of the target container image;

[0081] As an example, if the vulnerability detection result indicates that the target container image does not contain a vulnerability, the target container image is digitally signed to obtain the image signature of the target container image; for example, the image is signed using a relevant signature algorithm, and the signature generates a digital signature file. The digital signature file includes image metadata (such as image hash, version, creator, etc.), content summary, etc., for subsequent signature verification.

[0082] (3) Generate an image resource based on the target container image and the image signature.

[0083] Then, the target container image and the image signature are packaged to generate the image resource.

[0084] Step 505: perform signature verification on the target container image according to the image signature.

[0085] In the disclosed embodiment, the proxy edge node uses the image signature to verify the integrity and legitimacy of the target container image. For example, it uses the public key of the trusted source to verify whether the signature is valid and whether the image content of the target container image has been tampered with.

[0086] Step 506 : In response to the target container image passing the signature verification, the target container image is loaded into the target engine.

[0087] As an example, if the target container image passes the signature verification, indicating that the image is trustworthy and has not been tampered with, the proxy edge node loads the target container image to the target engine.

[0088] As another example, in response to the target container image failing the signature verification, the target container image is refused to be loaded into the target engine, and an alarm message is generated; wherein the alarm message is used to indicate that the target container image fails the signature verification.

[0089] To improve the security and controllability of the system and prevent malicious or illegal images from being deployed and run, in the disclosed embodiment, during the signature verification process of the target container image, if it is found that the image fails the verification, the proxy edge node will refuse to load it into the local target container engine to prevent the execution of potentially illegal or tampered images. At the same time, the proxy edge node will generate a corresponding alarm message to indicate that the container image has failed the signature verification, and report the alarm message to the virtual edge node or the central cloud platform, thereby achieving security control and abnormal warning during the image distribution process.

[0090] Step 507 : Invoke the target engine and, based on the target container image, perform a container control operation adapted to the target container image on the target container instance.

[0091] Furthermore, after the image is loaded, the proxy edge node can further use the image to perform container control operations on the target container instance that are adapted to the target container image; for example, creating a new target container instance; for example, updating the image version used by an existing target container instance; for example, starting, restarting, or rebuilding the target container instance, etc.

[0092] It should be noted that the execution process of steps 501 to 503 can be implemented in any of the embodiments of the present disclosure, and the embodiments of the present disclosure do not limit this and will not be described in detail.

[0093] In summary, after receiving the image distribution message, the image resource in the container management message is extracted, and the signature of the target container image in the image resource is verified based on the digital signature in the image resource. After the verification passes, the image is loaded into the local container engine, and the engine is further called to perform container control operations adapted to the target container image. This not only achieves accurate identification and secure loading of container images, but also supports automated container deployment based on trusted images, significantly improving the security, controllability and operation and maintenance efficiency of the system.

[0094] Based on the above embodiments, Figure 6As shown, the communication method of the embodiment of the present disclosure can also be implemented based on the following steps, the specific steps are as follows:

[0095] (1) Image scanning and signing (central cloud side)

[0096] 1) Image vulnerability scanning mechanism

[0097] After the application container image is built, the central cloud platform first performs an automated vulnerability scan on the image to ensure that it does not contain known security vulnerabilities or malicious code. The scanning tool can integrate mainstream open source or commercial vulnerability libraries for real-time comparison;

[0098] 2) Algorithm signature

[0099] The image is signed using a related algorithm (such as SM2). The signature generates a digital signature file that includes image metadata (such as image hash, version, creator, etc.) and content summary for subsequent edge signature verification.

[0100] 3) Upload to the trusted image repository

[0101] After the signature is completed, the image together with the signature information is uploaded to the trusted image warehouse in the central cloud. The warehouse only accepts image uploads that have passed vulnerability scanning and signature authentication, and serves as the only trusted source for sending to edge devices.

[0102] (2) Image push and scheduling (from central cloud to edge)

[0103] The virtual edge node encapsulates the image's file data, metadata, signature information, and other contents as an image distribution task, and pushes them to the proxy edge node through a one-way network channel.

[0104] (3) Image signature verification and local loading (physical edge node)

[0105] 1) The proxy edge node receives the image and verifies the signature;

[0106] After receiving the image distribution task, the proxy edge node first extracts the container image and its digital signature information from the push request, and then uses the relevant algorithm to verify the signature of the image content;

[0107] If the signature verification is successful, it means that the image has not been tampered with and the source is trustworthy. The proxy edge node imports it into the local container engine (such as Docker).

[0108] If the signature verification fails, the proxy edge node refuses to load the image and records the security warning information. At the same time, the virtual edge node obtains the status information of the application signature verification failure by synchronizing the status of the proxy edge node and records it.

[0109] 2) Container operation and container creation

[0110] Verified images are used to create and run containers. The proxy edge node completes the deployment according to the container specifications issued by the virtual edge node and maintains consistency with the container lifecycle management.

[0111] In order to clearly illustrate how to call the target engine in the above embodiment and execute the target container management policy adapted to the message type on the target container instance, the present disclosure proposes another communication method.

[0112] Figure 7 FIG5 is a flow chart of a communication method according to the fifth embodiment of the present disclosure. It should be noted that the embodiment of the present disclosure is applied to a proxy edge node.

[0113] like Figure 7 As shown, the communication method includes the following steps:

[0114] Step 701: Receive a container management message sent by a virtual edge node.

[0115] Step 702: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0116] Step 703: Determine the target container instance according to the container identification information in the message content and at least one container instance in the local container.

[0117] Step 704 : In the case where the message type includes a monitoring data collection request, respond to the monitoring data collection request and collect the operating indicators of the target container instance and the status indicators of the physical edge node.

[0118] As a possible implementation method, when the received message is a monitoring data collection request for collecting monitoring data, respond to the monitoring data collection request and collect the operating indicators of the target container instance and the status indicators of the entity edge node, where the operating indicators may include but are not limited to: CPU usage, memory usage, network I / O traffic, etc., and the status indicators may include but are not limited to: CPU, memory, disk usage, temperature, power status, etc.

[0119] Step 705: Generate a monitoring data response to the monitoring data request based on the operation indicator and the status indicator.

[0120] In order to facilitate the central cloud to process the monitoring data, the collected data is structured and organized to form a standardized monitoring response data packet.

[0121] Step 706: Send the monitoring data response to the virtual edge node.

[0122] Then, the generated monitoring data response is sent back to the virtual edge node, wherein the monitoring data response can be used for data monitoring and analysis in the central cloud.

[0123] It should be noted that the execution process of steps 701 to 703 can be implemented in any of the embodiments of the present disclosure, and the embodiments of the present disclosure do not limit this and will not be described in detail.

[0124] In summary, after receiving the monitoring data collection request, the operating indicators of the target container instance and the status indicators of the physical edge node are collected, and they are encapsulated into standardized monitoring data responses and finally sent to the virtual edge node. In this way, not only the remote perception of the operating status of the edge container and node is realized, but also the reliable return and centralized management of monitoring data in a restricted environment where the edge device cannot actively initiate a connection and only supports receiving instructions in a one-way network communication scenario is realized.

[0125] In order to clearly illustrate how to call the target engine in the above embodiment and execute the target container management policy adapted to the message type on the target container instance, the present disclosure proposes another communication method.

[0126] Figure 8 It is a flow chart of a communication method according to the sixth embodiment of the present disclosure. It should be noted that the embodiment of the present disclosure is applied to a proxy edge node.

[0127] like Figure 8 As shown, the communication method includes the following steps:

[0128] Step 801: Receive a container management message sent by a virtual edge node.

[0129] Step 802: Perform structured parsing on the container management message to obtain the message content and message type of the container management message.

[0130] Step 803: Determine the target container instance according to the container identification information in the message content and at least one container instance in the local container.

[0131] Step 804 : In case the message type includes a log collection request, respond to the log collection request and collect log data of the target container instance.

[0132] As a possible implementation manner, when the message type indicates that the container management message is a log collection request for log collection, log data is collected for the target container instance in response to the log collection request.

[0133] Step 805 : Organize and classify the log data according to the attribute information of the target container instance, and generate a log collection response to the log collection request based on the organized and classified log data.

[0134] To facilitate subsequent analysis and presentation, in an embodiment of the present disclosure, the attribute information of the target container instance may include, but is not limited to, container ID / name, service or application identifier, etc. Furthermore, based on the attribute information of the target container instance, the log data is categorized and organized; for example, logs may be divided by service, sorted by time, and classified by log level.

[0135] Step 806: Send the log collection response to the virtual edge node.

[0136] Then, the organized logs are encapsulated into a structured log collection response, and the generated log response data is sent back to the virtual edge node for viewing and analysis.

[0137] It should be noted that the execution process of steps 801 to 803 can be implemented in any of the embodiments of the present disclosure, and the embodiments of the present disclosure do not limit this and will not be described in detail.

[0138] In summary, when the message type includes a log collection request, the log collection request is responded to and the log data of the target container instance is collected; the log data is organized and classified according to the attribute information of the target container instance, and a log collection response to the log collection request is generated based on the organized and classified log data; the log collection response is sent to the virtual edge node, thereby realizing the collection and centralized management of the container instance logs in the edge device, and at the same time realizing the stable return and observability of the edge log data in a restricted network environment such as one-way communication.

[0139] Based on the above embodiments, Figure 9 As shown, the communication method of the embodiment of the present disclosure may include the following steps:

[0140] (1) Monitoring data collection mechanism of physical edge nodes

[0141] 1) The monitoring and collection framework is compatible with Prometheus (an open source system monitoring and alerting toolkit)

[0142] Deploy the Prometheus monitoring system in the central cloud as a unified data collection and display platform. The virtual edge node (EdgeKubelet) introduced in the system has similar monitoring interface exposure capabilities and can provide standard pull interfaces (such as Get / metrics) for the monitoring system.

[0143] 2) Data collection path design

[0144] Due to the one-way communication limitation, EdgeAgent cannot actively report monitoring indicator data from edge nodes. To this end, EdgeKubelet actively pulls monitoring data from edge devices through a one-way network link. The specific process is as follows:

[0145] 1. The virtual edge node (EdgeKubelet) sends a monitoring data request to the agent edge node (EdgeAgent) of the physical edge node;

[0146] 2. The proxy edge node collects container operation indicators (such as CPU, memory, IO, network traffic, etc.) and status indicators of the physical edge node;

[0147] 3. The proxy edge node encapsulates the data in a preset format and returns it to the virtual edge node through a one-way network channel;

[0148] 4. The virtual edge node organizes the data and exposes it to the monitoring system through its / metrics interface.

[0149] (2) Edge node log collection mechanism

[0150] 1) The log collection framework is compatible with ElasticSearch (an open source search engine)

[0151] ElasticSearch is deployed in the central cloud as a log aggregation and query platform. The virtual edge node in this application can realize the unified collection and reporting of physical edge node logs;

[0152] 2) Data collection path design

[0153] Virtual edge nodes cannot directly collect logs from local containers. To this end, the system uses the following process:

[0154] 1. The virtual edge node sends log data pull requests to the proxy edge node regularly or on demand;

[0155] 2. The virtual edge node collects log output from the local container's running environment;

[0156] 3. The proxy edge node organizes log data by tags such as timestamp, PodID, and container name;

[0157] 4. Return to the virtual edge node through a unidirectional network uplink channel;

[0158] 5. The virtual edge node reports the log data to ElasticSearch in a unified manner.

[0159] Corresponding to the communication method provided in the above embodiment, the present disclosure also provides a communication device. Since the communication device provided in the embodiment of the present disclosure corresponds to the communication method provided in the above embodiment, the implementation of the communication method is also applicable to the communication device provided in the embodiment of the present disclosure, and will not be described in detail in the embodiment of the present disclosure.

[0160] Figure 10 This is a schematic diagram of the structure of the communication device shown in the seventh embodiment of the present disclosure. It should be noted that the device can be applied to a proxy edge node, which is deployed between a virtual edge node and a target engine. The target engine is used to manage the local container of the physical edge node that the proxy edge node proxies.

[0161] like Figure 10 As shown, the communication device 1000 includes: a receiving module 1010 , a parsing module 1020 and a processing module 1030 .

[0162] Among them, the receiving module 1010 is used to receive the container management message sent by the virtual edge node; the parsing module 1020 is used to perform structured parsing on the container management message to obtain the message content and message type of the container management message; the processing module 1030 is used to call the target engine to execute the target container management policy on the target container instance in the local container based on the message content and message type.

[0163] As a possible implementation of an embodiment of the present disclosure, processing module 1030 is configured to determine a target container instance based on container identification information in the message content and at least one container instance in the local container; and to call a target engine to execute a target container management policy adapted to the message type on the target container instance.

[0164] As a possible implementation of an embodiment of the present disclosure, processing module 1030 is configured to, when the message type includes a container control instruction, identify a container control type from the message content; and, based on the container control type, call a target engine to perform a lifecycle control operation adapted to the container control type on the target container instance.

[0165] As a possible implementation of the embodiment of the present disclosure, the communication device 1000 further includes: a sending module.

[0166] Among them, the sending module is used to receive a container status query request sent by the virtual edge node; respond to the container status query request, obtain the status information of the target container instance, and generate a container status query response based on the status information; and send the container status query response to the virtual edge node.

[0167] As a possible implementation method of an embodiment of the present disclosure, the processing module 1030 is used to extract the image resources in the message content when the message type includes image distribution; wherein the image resources include the target container image and the image signature of the target container image; based on the image signature, the target container image is signature verified; in response to the target container image passing the signature verification, the target container image is loaded into the target engine; the target engine is called to perform container control operations adapted to the target container image on the target container instance based on the target container image.

[0168] As a possible implementation of an embodiment of the present disclosure, processing module 1030 is configured to, in response to a target container image failing signature verification, refuse to load the target container image into the target engine and generate an alarm message; wherein the alarm message is used to indicate that the target container image fails signature verification.

[0169] As a possible implementation of the embodiment of the present disclosure, the image resource is generated using the following modules: a detection module, a signature module, and a generation module.

[0170] Among them, the detection module is used to perform vulnerability detection on the target container image in response to the completion of the creation of the target container image to obtain the vulnerability detection result of the target container image; the signature module is used to digitally sign the target container image in response to the vulnerability detection result indicating that the target container image does not contain vulnerabilities to obtain the image signature of the target container image; the generation module is used to generate image resources based on the target container image and the image signature.

[0171] As a possible implementation method of an embodiment of the present disclosure, the processing module 1030 is used to respond to a monitoring data collection request when the message type includes a monitoring data collection request, collect the operating indicators of the target container instance and the status indicators of the physical edge node; generate a monitoring data response to the monitoring data request based on the operating indicators and the status indicators; and send the monitoring data response to the virtual edge node.

[0172] As a possible implementation of an embodiment of the present disclosure, processing module 1030 is configured to, when the message type includes a log collection request, respond to the log collection request and collect log data of the target container instance; organize and classify the log data according to attribute information of the target container instance, and generate a log collection response to the log collection request based on the organized and classified log data; and send the log collection response to the virtual edge node.

[0173] The communication device of the embodiment of the present disclosure sets up virtual edge nodes and proxy edge nodes in the system. The proxy edge nodes receive container management messages sent by the virtual edge nodes, thereby realizing that container management messages from the central cloud can be reliably received in a one-way network scenario. Furthermore, the proxy edge nodes perform structured parsing on the received container management messages, and extract the message content and message type therefrom, so that even in the absence of real-time interaction capabilities, the edge devices can accurately understand the management intentions and specific operating parameters of the central cloud, thereby effectively ensuring the accurate parsing and accurate execution of container management messages. Finally, based on the parsed message content and message type, the proxy edge node calls the local target container engine and executes the corresponding container management policy on the target container instance, thereby realizing the complete mapping and automatic execution of container operation instructions from the central cloud to the edge device, and significantly improving the management accuracy and effectiveness of the physical edge nodes in a restricted network environment.

[0174] In an exemplary embodiment, an electronic device is also provided.

[0175] Among them, electronic equipment includes:

[0176] processor;

[0177] a memory for storing processor-executable instructions;

[0178] The processor is configured to execute instructions to implement the communication method proposed in any of the aforementioned embodiments.

[0179] As an example, Figure 11 is a structural diagram of an electronic device 1100 shown in an exemplary embodiment of the present disclosure. Figure 11 As shown, the electronic device 1100 may further include:

[0180] The memory 1110 and the processor 1120, and the bus 1130 connecting different components (including the memory 1110 and the processor 1120), the memory 1110 stores a computer program, and when the processor 1120 executes the program, the communication method described in the embodiment of the present disclosure is implemented.

[0181] Bus 1130 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.

[0182] The electronic device 1100 typically includes a variety of electronic device-readable media, which can be any available media that can be accessed by the electronic device 1100, including volatile and non-volatile media, removable and non-removable media.

[0183] The memory 1110 may also include computer system readable media in the form of volatile memory, such as random access memory (RAM) 1140 and / or cache memory 1150. The server 1100 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 1160 may be used to read and write non-removable, non-volatile magnetic media ( Figure 11 Not shown, often called a "hard drive"). Although Figure 11 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 1130 via one or more data medium interfaces. Memory 1110 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments of the present disclosure.

[0184] A program / utility 1180 having a set (at least one) of program modules 1170 may be stored, for example, in memory 1110. Such program modules 1170 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 1170 generally implement the functions and / or methods described in the embodiments of the present disclosure.

[0185] Electronic device 1100 can also communicate with one or more external devices 1190 (e.g., a keyboard, pointing device, display 1191, etc.), one or more devices that enable a user to interact with electronic device 1100, and / or any device that enables electronic device 1100 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication can occur via input / output (I / O) interface 1192. Furthermore, electronic device 1100 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via network adapter 1193. As shown, network adapter 1193 communicates with other modules of electronic device 1100 via bus 1130. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with electronic device 1100, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0186] The processor 1120 executes the programs stored in the memory 1110 to perform various functional applications and data processing.

[0187] It should be noted that the implementation process and technical principles of the electronic device of this embodiment can be found in the aforementioned explanation of the communication method of the embodiment of the present disclosure, and will not be repeated here.

[0188] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory including instructions. The instructions can be executed by a processor of an electronic device to perform the communication method provided in any of the above embodiments. Alternatively, the computer-readable storage medium can be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.

[0189] In an exemplary embodiment, a computer program product is further provided, including a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the communication method proposed in any of the above embodiments.

[0190] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0191] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A communication method, characterized in that: Applied to a proxy edge node, the proxy edge node is arranged between a virtual edge node and a target engine, the target engine is used to manage a local container of a physical edge node proxied by the proxy edge node, the method comprising: receiving a container management message sent by the virtual edge node; Performing structured parsing on the container management message to obtain the message content and message type of the container management message; According to the message content and the message type, a target engine is called to execute a target container management policy on the target container instance in the local container.

2. The method according to claim 1, characterized in that The calling of the target engine to execute the target container management policy on the target container instance in the local container according to the message content and the message type includes: Determine a target container instance according to the container identification information in the message content and at least one container instance in the local container; The target engine is called to execute a target container management policy adapted to the message type on the target container instance.

3. The method according to claim 2, characterized in that The calling of the target engine to execute a target container management policy adapted to the message type on the target container instance includes: In a case where the message type includes a container control instruction, identifying the container control type from the message content; According to the container control type, the target engine is called to perform a lifecycle control operation adapted to the container control type on the target container instance.

4. The method according to claim 3, characterized in that The method further comprises: receiving a container status query request sent by the virtual edge node; Responding to the container status query request, obtaining status information of the target container instance, and generating a container status query response based on the status information; Send the container status query response to the virtual edge node.

5. The method according to claim 2, characterized in that The calling of the target engine to execute the target container management policy on the target container instance in the local container according to the message content and the message type includes: In the case where the message type includes image distribution, extracting the image resource in the message content; wherein the image resource includes the target container image and the image signature of the target container image; Performing signature verification on the target container image according to the image signature; In response to the target container image passing the signature verification, loading the target container image into the target engine; The target engine is called to perform, on the target container instance based on the target container image, a container control operation adapted to the target container image.

6. The method according to claim 5, characterized in that The method further comprises: In response to the target container image failing the signature verification, refusing to load the target container image into the target engine, and generating an alarm message; wherein the alarm message is used to indicate that the target container image fails the signature verification.

7. The method according to claim 5, characterized in that The image resource is generated using the following steps: In response to the target container image being created, performing vulnerability detection on the target container image to obtain a vulnerability detection result of the target container image; In response to the vulnerability detection result indicating that the target container image does not contain a vulnerability, digitally signing the target container image to obtain an image signature of the target container image; The image resource is generated according to the target container image and the image signature.

8. The method according to claim 2, characterized in that The calling the target engine to execute the target container management policy on the target container instance includes: In a case where the message type includes a monitoring data collection request, responding to the monitoring data collection request, collecting the operating indicators of the target container instance and the status indicators of the entity edge node; generating a monitoring data response to the monitoring data request according to the operation indicator and the status indicator; The monitoring data response is sent to the virtual edge node.

9. The method according to claim 2, characterized in that The calling of the target engine to execute the target container management policy on the target container instance in the local container according to the message content and the message type includes: In a case where the message type includes a log collection request, responding to the log collection request to collect log data of the target container instance; Organizing and classifying the log data according to the attribute information of the target container instance, and generating a log collection response to the log collection request based on the organized and classified log data; The log collection response is sent to the virtual edge node.

10. A communication device, characterized in that: Applied to a proxy edge node, the proxy edge node is arranged between a virtual edge node and a target engine, the target engine is used to manage the local container of the physical edge node proxied by the proxy edge node, the device includes: A receiving module, configured to receive container management messages sent by the virtual edge node; a parsing module, configured to perform structured parsing on the container management message to obtain the message content and message type of the container management message; The processing module is configured to call a target engine to execute a target container management policy on a target container instance in the local container according to the message content and the message type.

Citation Information

Patent Citations

  • Server-free cloud service system, resource management method thereof and electronic equipment

    CN110837407A

  • Computing resource management scheduling method for industrial edge nodes

    CN111813502A

  • Node access method, device and apparatus and computer readable storage medium

    CN112165532A

  • Intelligent edge equipment control platform based on KubeEdge and Edge X Foundry

    CN112383416A

  • Edge cloud collaboration method and device

    CN113630383A