Kubernetes API resource integrity protection method and system
By introducing the Lease mechanism in Kubernetes, dual monitoring of Pod creation and deletion is achieved, solving the resource waste and execution integrity problems caused by repeated Pod startup, and ensuring Pod uniqueness and system stability.
Patent Information
- Application Number
- CN202510783853.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-09-23
AI Technical Summary
Repeated Pod startup in Kubernetes leads to resource waste and compromised program execution integrity. Existing mechanisms cannot effectively monitor the actual running status of Pods in the data plane, especially when attackers invade, and cannot be detected and handled in a timely manner.
The Lease mechanism is introduced to ensure Pod uniqueness by generating and monitoring leases, implement dual monitoring of Pod creation and deletion, and prevent Pod from being started repeatedly.
Effectively prevent Pod from being started repeatedly, ensure Pod uniqueness and program execution integrity, and avoid resource waste and performance impact.
Smart Images

Figure CN120688096A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of cloud native technology and resource management technology, and in particular to a general Kubernetes API resource protection method and system. Background Art
[0002] The container orchestration platform Kubernetes faces potential risks when orchestrating services, potentially leading to repeated startup of Pods, the smallest deployable and schedulable units in Kubernetes, resulting in wasted resources and compromised program execution integrity. A Pod is typically composed of one or more closely associated containers that share the same network namespace and storage volumes. For example, during Kubernetes operation, there is the risk of attackers invading worker nodes and Kubernetes itself failing, potentially leading to repeated startup of Pods, wasted resources, and compromised program execution integrity. After intrusion, attackers may maliciously launch additional Pods to occupy resources, while Kubernetes failures may cause Pods to be incorrectly restarted due to software defects, misconfigurations, or network issues. Both of these situations waste resources and compromise program execution integrity, impacting cluster performance and the normal operation of applications. Therefore, it is crucial to add safeguards to Pod startup to ensure the integrity of its execution process.
[0003] Although Kubernetes has multiple mechanisms to prevent duplicate Pod startups, such as controllers and schedulers that ensure the control plane's Pod count meets the desired state, container lifecycle management that automatically restarts failed containers, health checks and probes that monitor Pod status, and Pod storage uniqueness that ensures uniqueness during the creation phase, these mechanisms primarily target the control plane and cannot effectively monitor the actual number of Pods running on each node in the data plane. They also lack real-time monitoring and dual verification of Pod startup and deletion processes. This is especially true when an attacker compromises multiple nodes and replays control plane requests, potentially starting the same Pod on multiple nodes simultaneously. This can prevent the control plane from detecting and addressing this issue in a timely manner, ultimately compromising runtime integrity, wasting resources, and compromising program execution integrity. Summary of the Invention
[0004] To address these shortcomings, the present invention proposes a Kubernetes API resource integrity protection method and system. This general Kubernetes API resource integrity protection solution introduces a lease mechanism to prevent pod duplication, ensuring pod uniqueness and program execution integrity. The introduction of a lease mechanism ensures that Kubernetes data plane API resources are scheduled as expected, meeting integrity requirements.
[0005] In a first aspect, the present invention provides a Kubernetes API resource integrity protection method, comprising the following steps:
[0006] Generate the definition of the lease mechanism for the minimum deployable and schedulable unit on any tenant node through the container orchestration platform;
[0007] Create a lease mechanism corresponding to the minimum deployable and schedulable unit on the tenant node according to the definition;
[0008] The control plane module performs dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node, and the deletion of the minimum deployable and schedulable unit and the lease mechanism.
[0009] In some embodiments, the step of generating a definition of a lease mechanism for the minimum deployable and schedulable unit on any tenant node through the container orchestration platform further includes: reading configuration information of the minimum deployable and schedulable unit Pod through the container orchestration platform Kubelet, and generating a corresponding lease mechanism definition based on the configuration information.
[0010] In some embodiments, the step of dually monitoring the creation of the minimum deployable and schedulable unit on the corresponding tenant node, the deletion of the minimum deployable and schedulable unit, and the lease mechanism by the control plane module further includes:
[0011] In some embodiments, the control plane module monitors the creation of the minimum deployable and schedulable unit of the corresponding tenant node. If the control plane module does not receive the Pod startup readiness result, the rescheduling mechanism of the container orchestration platform Kubeletes is executed to automatically move the running Pod from one node to another. If the minimum deployable and schedulable unit is monitored to be ready for startup, the control plane module checks whether the Lease mechanism corresponding to the Pod exists. If not, the minimum deployable and schedulable unit is marked as unavailable.
[0012] In some embodiments, the control plane module monitors the deletion of the minimum deployable and schedulable unit of the corresponding tenant node, and the corresponding tenant node initiates a minimum deployable and schedulable unit deletion request, which is received and processed by the API Server, and then initiates a minimum deployable and schedulable unit stop and deletion request to the tenant node; the container orchestration platform Kubelet on the tenant node deletes the corresponding Pod and replies with the deletion result. If the deletion result is successful, the control plane module monitors the minimum deployable and schedulable unit deletion event, and deletes the lease mechanism corresponding to the minimum deployable and schedulable unit.
[0013] In a second aspect, the present invention provides a container orchestration platform Kubernetes API resource integrity protection system, which includes a definition module, a creation module, a control plane module, and a monitoring module; wherein:
[0014] The definition module is responsible for generating the definition of the lease mechanism of the minimum deployable and scheduling unit on any node through the container orchestration platform Kubelet;
[0015] The creation module is responsible for creating a lease mechanism corresponding to the minimum deployable and scheduling unit on the tenant node according to the definition;
[0016] The control plane module is responsible for executing customized control of the monitoring module of the system;
[0017] The monitoring module is responsible for dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node, the deletion of the minimum deployable and schedulable unit and the lease mechanism through the control plane module.
[0018] In a third aspect, an electronic device includes: a memory, a processor, and a computer program stored on the memory and runnable on the processor, wherein the processor implements a Kubernetes API resource integrity protection method when executing the computer program.
[0019] In a fourth aspect, the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a Kubernetes API resource integrity protection method.
[0020] Compared with the prior art, the present invention has the following advantages:
[0021] 1) Designed a comprehensive control logic that monitors the creation and deletion of the minimum deployable and schedulable unit for corresponding tenant nodes. This solution introduces a lease mechanism to prevent duplicate pod startups, ensuring pod uniqueness and program execution integrity.
[0022] 2) Ensure that Kubernetes data plane API resources implement Pod startup scheduling as expected and meet integrity requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 This is an overall flow chart of a Kubernetes API resource integrity protection method according to Example 1 of the present invention.
[0024] Figure 2This is a module diagram of a Kubernetes API resource integrity protection system according to embodiment 2 of the present invention. DETAILED DESCRIPTION
[0025] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0026] Example 1
[0027] Figure 1 The overall process of a Kubernetes API resource integrity protection method provided by the present invention is shown. The specific steps are as follows:
[0028] Step 1: Generate the definition of the lease mechanism (i.e., the Lease mechanism) for the smallest deployable and schedulable unit Pod on any node through the container orchestration platform Kubelet. The specific execution process of this step is described as follows:
[0029] Step 1.1: A tenant of any tenant node initiates a request to create a Pod, the smallest deployable and schedulable unit. After receiving the request, the API Server obtains the scheduling information from the request and schedules the Pod, the smallest deployable and schedulable unit, to the corresponding node based on the scheduling information.
[0030] Step 1.2: The container orchestration platform Kubelet reads the configuration information of the smallest deployable and schedulable unit, the Pod, and generates a corresponding lease mechanism definition based on the configuration information. The lease definition is generated based on the Pod's configuration information, primarily specifying the Pod for which the lease is intended, based on the Pod's name and namespace. This definition includes issuing a lease to a node, granting it access to specific resources. The configuration described here specifically includes the Pod's basic information and scheduling information. The basic Pod information includes the Pod's name, namespace, unique identifier (UID), and node name. The Pod's scheduling information primarily includes the following: 1) Node Selector: This specifies that a Pod can only be scheduled on nodes with specific labels. 2) Node Affinity: This provides a more flexible node selection method, allowing the use of Boolean expressions to select nodes.
[0031] Specifically, the generated Lease definition includes the following aspects:
[0032] The object of the lease issuance: that is, the name and namespace of the Pod, which clearly specifies the Pod to which the lease is issued.
[0033] Lease holder (Holder): Usually the name of the node running the Pod, indicating which node has obtained access to the Pod resources.
[0034] Lease acquisition time (AcquireTime): records the time when the Lease is created, which is used to determine the validity of the lease and handle possible conflicts.
[0035] Lease renewal time (RenewTime): For leases that need to be renewed regularly, record the time of the last renewal to ensure that the lease remains valid within the validity period.
[0036] Step 2: Create a lease mechanism corresponding to the smallest deployable and schedulable unit pod on the tenant node based on the definition, and issue a lease to the smallest deployable and schedulable unit pod through the container orchestration platform Kubelet. The specific execution process of this step is described as follows:
[0037] Initiate a Lease mechanism creation request to the API Server and create the Lease mechanism according to the definition. If successful, start the smallest deployable and schedulable unit Pod and obtain resource access rights to the tenant node.
[0038] Step 3: The control plane module performs dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node, the deletion of the minimum deployable and schedulable unit, and the lease mechanism. The specific process of this step is described as follows:
[0039] The control plane module monitors the creation of the Pod, the minimum deployable and schedulable unit of the corresponding tenant node. If the control plane module does not receive the Pod startup readiness result, the rescheduling mechanism of the container orchestration platform Kubeletes is executed to automatically move the running Pod from one node to another. (Completed by the container orchestration platform Kubeletes). If the Pod is monitored to be ready for startup, the custom controller checks whether the corresponding Lease mechanism of the Pod exists. If not, the Pod is marked as unavailable.
[0040] The control plane module monitors the deletion of Pods, the smallest deployable and schedulable units for corresponding tenant nodes. When a tenant node initiates a Pod deletion request, the API server receives and processes it, then sends a Pod stop and deletion request to the tenant node. The Kubelet, the container orchestration platform on the tenant node, deletes the corresponding Pod and responds with a deletion result. If the deletion is successful, the control plane module monitors the Pod deletion event and cancels the corresponding Pod's lease mechanism.
[0041] Specifically, the control plane module belongs to the container orchestration platform Kubeletes and includes multiple modules with the API server as the core. Specifically, these modules include: API server, controller, scheduler, key-value storage etcd, and kubelet on worker nodes.
[0042] Example 2
[0043] Figure 2 The present invention provides a Kubernetes API resource integrity protection system, which specifically includes a definition module, a creation module, a control plane module, and a monitoring module.
[0044] The definition module is responsible for generating the lease mechanism (i.e., the lease mechanism) for the smallest deployable and schedulable unit Pod on any node through the container orchestration platform Kubelet.
[0045] A creation module is responsible for creating a lease mechanism corresponding to the minimum deployable and scheduling unit on the tenant node according to the definition;
[0046] The control plane module is responsible for executing customized control of the system's monitoring module;
[0047] The monitoring module is responsible for dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node and the deletion of the minimum deployable and schedulable unit and the lease mechanism through the control plane module.
[0048] In summary, through the above embodiments, the present invention implements dual monitoring of Pod creation and deletion, ensures the uniqueness of the Pod startup process, and effectively avoids the risk of resource waste and program execution integrity damage caused by repeated Pod startup.
[0049] In addition, based on similar inventive concepts, an embodiment of the present invention also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor implements the above method when executing the computer program.
[0050] In addition, based on similar inventive concepts, an embodiment of the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that the computer program implements the above method when executed by a processor.
[0051] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications made without departing from the principles of the present invention should also be considered to fall within the scope of protection of the present invention.
Claims
1. A Kubernetes API resource integrity protection method, characterized in that: The following steps are involved: Generate the definition of the lease mechanism for the minimum deployable and schedulable unit on any tenant node through the container orchestration platform; Create a lease mechanism corresponding to the minimum deployable and schedulable unit on the tenant node according to the definition; The control plane module performs dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node, and the deletion of the minimum deployable and schedulable unit and the lease mechanism.
2. A Kubernetes API resource integrity protection method according to claim 1, characterized in that: The step of generating a definition of a lease mechanism for the minimum deployable and schedulable unit on any tenant node through the container orchestration platform further includes: reading configuration information of the minimum deployable and schedulable unit Pod through the container orchestration platform Kubelet, and generating a corresponding lease mechanism definition based on the configuration information.
3. A Kubernetes API resource integrity protection method according to claim 1, characterized in that: The step of performing dual monitoring of creation of a minimum deployable and schedulable unit on a corresponding tenant node, deletion of the minimum deployable and schedulable unit, and the lease mechanism by the control plane module further includes: The control plane module monitors the creation of the minimum deployable and schedulable unit for the corresponding tenant node. If the control plane module does not receive the Pod startup readiness result, the rescheduling mechanism of the container orchestration platform Kubeletes is executed to automatically move the running Pod from one node to another. If the minimum deployable and schedulable unit is monitored to be ready for startup, the module checks whether the corresponding lease mechanism of the Pod exists. If not, the minimum deployable and schedulable unit is marked as unavailable. The control plane module monitors the deletion of the minimum deployable and schedulable unit of the corresponding tenant node. The corresponding tenant node initiates a minimum deployable and schedulable unit deletion request. After the API server receives and processes it, it initiates a minimum deployable and schedulable unit stop and deletion request to the tenant node. The container orchestration platform Kubelet on the tenant node deletes the corresponding Pod and responds with the deletion result. If the deletion result is successful, the control plane module monitors the minimum deployable and schedulable unit deletion event and deletes the lease mechanism corresponding to the minimum deployable and schedulable unit.
4. A Kubernetes API resource integrity protection system that implements a method according to claims 1 to 3, characterized in that: The system includes a definition module, a creation module, a control plane module, and a monitoring module; wherein: The definition module is responsible for generating the definition of the lease mechanism of the minimum deployable and scheduling unit on any node through the container orchestration platform Kubelet; The creation module is responsible for creating a lease mechanism corresponding to the minimum deployable and scheduling unit on the tenant node according to the definition; The control plane module is responsible for executing customized control of the monitoring module of the system; The monitoring module is responsible for dual monitoring of the creation of the minimum deployable and schedulable unit on the corresponding tenant node, the deletion of the minimum deployable and schedulable unit and the lease mechanism through the control plane module.
5. An electronic device comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements a Kubernetes API resource integrity protection method according to any one of claims 1 to 3 when executing the computer program.
6. A non-transitory computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the computer program implements a Kubernetes API resource integrity protection method according to any one of claims 1 to 3.