Security management method and device for virtualization cluster, equipment and medium
By directly using iptables tools and configuration files in the Kubernetes cluster, the problem of firewall configuration relying on specific plug-ins is solved, efficient, accurate and diversified firewall policies are implemented, and the cluster security and adaptability are improved.
Patent Information
- Application Number
- CN202510763818.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-10-14
AI Technical Summary
In existing technologies, the firewall configuration of Kubernetes clusters relies on specific network plug-ins, resulting in inconsistent firewall function support, making it difficult to meet diverse and scalable requirements, and difficult to achieve consistent and fine-grained firewall rules in multi-cluster environments.
By calling the iptables tool within the operating system of the target node, the configuration entries are directly converted into firewall rules, avoiding dependence on specific network plug-ins, and dynamically adjusting the firewall policy based on the configuration file and associated information to achieve unified and accurate firewall configuration.
It improves the efficiency and accuracy of firewall configuration, supports diverse firewall policies, enhances the security and scalability of virtualized clusters, and adapts to the needs of multi-cluster environments.
Smart Images

Figure CN120785574A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud computing technology, and in particular to a method, apparatus, device, and medium for secure management of a virtualized cluster. Background Art
[0002] Kubernetes is a container orchestration engine that supports automated deployment, massive scalability, and containerized application management. A pod is the smallest unit that can be created and deployed in Kubernetes, representing a process running in a virtualized cluster. To isolate and protect business logic from unauthorized access or attacks, you can set up firewalls for containers within a pod.
[0003] In the related technology, the method of configuring the firewall by installing a specific network plug-in that supports the Kubernetes network policy requires, on the one hand, the additional installation of a specific network plug-in, and different network plug-ins have different degrees of support for firewall functions. Selecting an incompatible network plug-in will result in the firewall function being restricted; on the other hand, the firewall policy implemented by the specific network plug-in is relatively simple, which is not conducive to improving the security of the Kubernetes cluster. Summary of the Invention
[0004] The embodiments of the present application provide a security management method, apparatus, device, and medium for a virtualization cluster, which does not require the installation of additional specific network plug-ins, improves the efficiency and convenience of firewall configuration for business containers, and improves the scalability and diversity of firewall configuration for business containers, thereby improving the security of the virtualization cluster.
[0005] The technical solution of the embodiment of the present application is implemented as follows:
[0006] In a first aspect, an embodiment of the present application provides a method for securely managing a virtualization cluster, the method comprising:
[0007] In response to the virtualization cluster creating a target container group, calling a target program pre-stored in a target node where the target container group is located;
[0008] Acquire association information of the target container group through the target program; wherein the association information includes at least one of the following items: various attribute information of the target node where the target container group is located, and various attribute information of the target container group;
[0009] Obtaining a configuration file of the virtualization cluster, and determining a target configuration item based on the configuration file and the associated information; wherein the configuration file is used to configure a firewall for the container group;
[0010] Performing firewall configuration on the service container in the target container group based on the target configuration entry;
[0011] The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
[0012] In a second aspect, an embodiment of the present application provides a security management device, including:
[0013] A calling module is configured to call a target program pre-stored in a target node where the target container group is located in response to the virtualization cluster creating the target container group;
[0014] a first acquisition module configured to acquire, through the target program, association information of the target container group; wherein the association information includes at least one of the following: various attribute information of the target node where the target container group is located, and various attribute information of the target container group;
[0015] A first determination module is configured to obtain a configuration file of the virtualization cluster and determine a target configuration item based on the configuration file and the association information; wherein the configuration file is used to configure a firewall for the container group;
[0016] a first configuration module, configured to perform firewall configuration on the service container in the target container group based on the target configuration entry;
[0017] The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
[0018] In a third aspect, an embodiment of the present application provides an electronic device, including:
[0019] Memory for storing computer programs or executable instructions;
[0020] The processor is used to implement the method provided in the first aspect of the embodiment of the present application when executing the computer program or executable instructions stored in the memory.
[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program or executable instructions are stored. When the computer program or executable instructions are executed by a processor, the method provided in the first aspect of the embodiment of the present application is implemented.
[0022] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program or executable instructions. When the computer program or executable instructions are executed by a processor, the method provided in the first aspect of the embodiment of the present application is implemented.
[0023] The embodiments of the present application have the following beneficial effects:
[0024] In the first aspect, the target program invokes a command line tool iptables in the operating system of the target node, so that the iptables can convert the target configuration entry into a firewall rule, thereby eliminating the need to convert the target configuration entry by using a CNI plug-in matched with a resource object NetworkPolicy of the virtualization cluster. Therefore, even if the CNI plug-in does not match the NetworkPolicy, the business container can be accurately configured with the firewall, thereby eliminating the need to additionally install a specific network plug-in, and improving the efficiency of the firewall configuration for the business container.
[0025] In the second aspect, by adjusting the configuration file, the firewall policy can be dynamically and uniformly configured, which is beneficial to improving the convenience of the firewall configuration. Meanwhile, based on the association information of the configuration file and the target container group, the accuracy of determining the target configuration entry is improved, thereby improving the precision of the firewall configuration for the business container.
[0026] In the third aspect, various firewall policies supported by the iptables can be implemented on the business container, thereby improving the expansibility and diversity of the firewall configuration for the business container, and further improving the security of the virtualization cluster. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 is a schematic architecture of a security management system provided by an embodiment of the present application Figure 1 .
[0028] Figure 2 is a schematic architecture of a security management system provided by an embodiment of the present application
[0029] Figure 3 is a schematic architecture of a security management system provided by an embodiment of the present application
[0030] Figure 4 is a schematic architecture of a security management system provided by an embodiment of the present application Figure 2 . DETAILED DESCRIPTION
[0031] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings, and the described embodiments should not be regarded as limiting the present application. All other embodiments obtained by a person of ordinary skill in the art without making creative efforts fall within the scope of protection of the present application.
[0032] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0033] In the following description, the terms "first\second\third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0034] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0035] Before further describing the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations.
[0036] (1) k8s, also known as kubernetes or k8s for short, is an abbreviation formed by replacing the eight characters "ubernete" with the number "8". k8s is an open source container orchestration engine that supports automated deployment, large-scale scalability, and application container management. It also provides numerous mechanisms for scalable operations on k8s resources, including permission control plug-ins, resource extensions, and resource quota management.
[0037] (2) Cluster resources: resources that can be allocated to Pods, such as CPU, memory, GPU cores, GPU memory, and cluster storage.
[0038] (3) Node: A node in a k8s cluster, which can be a physical server, virtual machine (VM) or cloud instance (such as AWS EC2, Azure VM), is used to provide CPU, memory, storage and network resources for Pod use.
[0039] (4) NetworkPolicy: A resource object in Kubernetes that defines communication rules between pods and between pods and external networks, thereby implementing fine-grained network access control. This resource object is the core mechanism of Kubernetes network policy, enhancing cluster security by controlling the source and destination of traffic.
[0040] Pod labels are key-value pairs used to identify the classification of Pods. NetworkPolicy is a Kubernetes resource object and an abstract network policy used to define the network access rules of Pods. It matches Pods with specific labels through selectors and restricts the network behavior of Pods. Suppose there is a Kubernetes cluster whose Pods include: a front-end service with label app=web, a database service with label app=db, and a cache service with label app=cache. The requirement is to allow Pods with label app=web to access Pods with label app=db. Then, by installing specific network plug-ins that support NetworkPolicy, such as Calico and Cilium, the NetworkPolicy rules can be converted into actual network isolation mechanisms, so that only Pods with label app=web can access Pods with label app=db, and other Pods (such as app=cache) cannot access Pods with label app=db.
[0041] Traditional Kubernetes NetworkPolicy is dynamically applied based on Pod labels. However, in some scenarios, more fine-grained control is required (such as based on IP, port, or custom fields). In this case, fine-grained firewall rules are pre-stored in Pod annotations. At the same time, in multi-cluster or multi-cloud environments, the network policies of different clusters may be inconsistent, leading to security vulnerabilities. By explicitly declaring firewall rules at the Pod level through annotations, the consistency and portability of firewall rules are ensured.
[0042] In related technologies, specific network plug-ins only need to focus on the network configuration of the business container (such as IP allocation and routing rules). Therefore, specific network plug-ins will not actively access the Kubernetes program interface or Pod annotations to limit the scope of the network plug-in's permissions, thereby reducing the risk of Pod attacks or misoperations.
[0043] In addition, network plug-ins usually configure firewalls based on Pod labels. Even if Pod annotations are obtained through the Kubernetes program interface, firewall configuration cannot be performed based on Pod annotations. For example, the network plug-in version does not support parsing Pod annotations, the network plug-in does not enable related functions, or the network plug-in is not deployed correctly, resulting in the inability to parse Pod annotations. As a result, it cannot meet the more fine-grained control requirements in certain scenarios and the consistency requirements of firewall rules in multiple clusters, which is not conducive to improving cluster security.
[0044] To address the above-mentioned issues, embodiments of the present application provide a method, apparatus, device, computer-readable storage medium, and computer program product for virtualization cluster security management. A target program invokes the command-line tool iptables within the target node's operating system, enabling iptables to convert target configuration entries into firewall rules. Therefore, even if the CNI plugin and NetworkPolicy do not match, accurate firewall configuration can be performed on the service container, eliminating the need to install additional specific network plugins and improving the efficiency of firewall configuration for the service container. Furthermore, by adjusting the configuration file, firewall policies can be dynamically and uniformly configured, facilitating improved firewall configuration convenience. Furthermore, based on the association between the configuration file and the target container group, the accuracy of determining target configuration entries is improved, thereby improving the precision of firewall configuration for the service container. Furthermore, various firewall policies supported by iptables can be implemented on the service container, thereby increasing the scalability and diversity of firewall configuration for the service container and, in turn, enhancing the security of the virtualization cluster.
[0045] The following describes an electronic device for implementing the above-mentioned security management method provided in an embodiment of the present application. The electronic device provided in an embodiment of the present application can be implemented as various types of terminal devices such as laptop computers, desktop computers, mobile devices, etc., and can also be implemented as a backend server of a network platform (hereinafter referred to as a server). The following describes an exemplary application when the electronic device is implemented as a server of a network platform.
[0046] See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of a security management system provided by the embodiment of the present application. Figure 1 In order to implement the security management method provided in the embodiment of the present application, the terminal device 101 (the number of terminal devices included in the security management system of the embodiment of the present disclosure is not limited) is connected to the server 102 through the network 103. The network 103 can be a wide area network or a local area network, or a combination of the two.
[0047] In some possible implementations, a user may log in to an application corresponding to the network platform through a terminal device 101, and the terminal device 101 interacts with the server 102 through a network 103. The server 102, in response to the virtualization cluster creating a target container group, calls a target program pre-stored in a target node where the target container group is located through the network 103; obtains association information of the target container group through the target program; wherein the association information includes at least one of the following items: various attribute information of the target node where the target container group is located, and various attribute information of the target container group; obtains a configuration file of the virtualization cluster, and determines a target configuration item based on the configuration file and the association information; wherein the configuration file is used to perform firewall configuration for the container group; and based on the target configuration item, performs firewall configuration for the service container in the target container group; wherein the target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration item into a firewall rule and send the processing result to the terminal device 101.
[0048] In some embodiments, the server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, and big data and artificial intelligence platforms. The terminal device 101 can be a smart phone, tablet computer, laptop computer, desktop computer, smart watch, etc., but is not limited to this. The terminal device and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in the embodiments of the present application.
[0049] See also Figure 2 , Figure 2 is a structural diagram of an electronic device provided in an embodiment of the present application; wherein, Figure 2 The electronic device 200 shown includes: at least one processor 210, a memory 250, at least one network interface 220 and a user interface 230. The various components in the electronic device 200 are coupled together via a bus system 240. It is understood that the bus system 240 is used to achieve connection and communication between these components. In addition to including a data bus, the bus system 240 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, the bus system 240 is not described in detail. Figure 2 Various buses are labeled as bus system 240 .
[0050] The processor 210 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.
[0051] The user interface 230 includes one or more output devices 231 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 230 also includes one or more input devices 232, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.
[0052] The memory 250 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard drives, optical drives, etc. The memory 250 may optionally include one or more storage devices that are physically remote from the processor 210.
[0053] The memory 250 includes volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 250 described in the embodiments of the present application is intended to include any suitable type of memory.
[0054] In some embodiments, the memory 250 can store data to support various operations, examples of which include programs, modules, and data structures, or a subset or superset thereof, as exemplified below.
[0055] Operating system 251, including system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and process hardware-based tasks;
[0056] A network communication module 252 for reaching other computing devices via one or more (wired or wireless) network interfaces 220 , exemplary network interfaces 220 including Bluetooth, WiFi, and USB;
[0057] a presentation module 253 for enabling presentation of information via one or more output devices 231 (e.g., a display screen, a speaker, etc.) associated with the user interface 230 (e.g., a user interface for operating peripheral devices and displaying content and information);
[0058] The input processing module 254 is configured to detect one or more user inputs or interactions from one of the one or more input devices 232 and to translate the detected inputs or interactions.
[0059] In some embodiments, the security management device provided in the embodiments of the present application can be implemented in software. Figure 2 The security management device 255 stored in the memory 250 is shown. This device can be software in the form of a program or plug-in, and includes the following software modules: a calling module 2551, a first acquisition module 2552, a first determination module 2553, and a first configuration module 2554. These modules are logical and can be arbitrarily combined or further separated according to the functions they implement. The functions of each module will be described below.
[0060] In other embodiments, the security management device provided in the embodiments of the present application can be implemented in hardware. As an example, the device provided in the embodiments of the present application can be a processor in the form of a hardware decoding processor, which is programmed to execute the security management method provided in the embodiments of the present application. For example, the processor in the form of a hardware decoding processor can adopt one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs) or other electronic components.
[0061] The security management method provided in the embodiments of the present application will be described below in conjunction with the exemplary application and implementation of the electronic device provided in the embodiments of the present application.
[0062] See also Figure 3 , Figure 3 FIG. 1 is a flow chart of a method for managing a virtualized cluster security provided by an embodiment of the present application. Figure 3 As shown, the following steps may be included:
[0063] In step 301, in response to the virtualization cluster creating a target container group, a target program pre-stored in a target node where the target container group is located is called;
[0064] In step 302, in response to obtaining the associated information of the target container group through the target program, the associated information includes at least one of the following: various attribute information of the target node where the target container group is located, and various attribute information of the target container group;
[0065] In step 303, a configuration file of the virtualization cluster is obtained, and a target configuration item is determined based on the configuration file and associated information; wherein the configuration file is used to configure the firewall of the container group;
[0066] In step 304, firewall configuration is performed on the service containers in the target container group based on the target configuration entry;
[0067] The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
[0068] Here, the Pods on the target node include but are not limited to those created by controllers such as Deployment, StatefulSet, or DaemonSet.
[0069] For example, when a new node is added to a virtualized cluster, DaemonSet automatically creates a corresponding Pod on that node. When a node is removed, DaemonSet automatically cleans up the Pods on that node. DaemonSet Pods are node-bound; each Pod is scheduled to a specific node. If a node is unavailable (for example, if it's down or marked as unschedulable), DaemonSet does not create a Pod on that node.
[0070] In some embodiments, every node in a Kubernetes cluster may become an attack entry point, especially when Worker nodes directly expose external traffic (such as through NodePort or LoadBalancer services), and external traffic will directly access the Pod on the node. Deploying a firewall through DaemonSet can ensure that each node has unified security protection capabilities and avoid security vulnerabilities caused by the lack of node protection. In addition, DaemonSet can ensure that a firewall Pod runs on each node in the cluster, automatically deploys when a new node is added, and automatically cleans up when a node is removed. This automated mechanism simplifies operation and maintenance work and avoids the complexity and omissions of manual configuration.
[0071] Here, the firewall Pod deployed by the DaemonSet pre-stores the target program firewall, which is used to call command-line tools within the target node's operating system, such as iptables. Specifically, in the firewall configuration scenario, iptables is a native operating system tool and an intermediary layer for manipulating iptables rules. It converts rules defined by the virtualization cluster administrator (for example, DROP 192.168.1.100) into binary instructions executable by the target node's operating system kernel. Furthermore, during actual communication interactions, iptables can execute firewall rules, matching and filtering network packets through chained rules.
[0072] In some embodiments, the target program is written based on the Go language (Golang). When the target node is deployed by DaemonSet, the target program is stored in the firewall Pod, and the firewall Pod is encapsulated in the target node.
[0073] In some embodiments, the rules of NetworkPolicy are relatively fixed, mainly supporting simple filtering based on IP addresses, ports and protocols, and do not support some advanced network policy functions, for example: time-based access control (such as "allow access only on weekdays"), deep packet inspection based on application layer protocols (such as "only allow HTTP requests, deny FTP"), dynamic rule updates (such as adjusting rules based on external configuration files or API responses) and integration with external security systems (such as linkage with SIEM, IDS / IPS systems).
[0074] In some embodiments, the target program can bypass the limitations of NetworkPolicy and directly implement various firewall policies supported by iptables on the target node to implement more complex firewall rules. Exemplary, complex firewall rules include but are not limited to: dynamically adjusting rules based on time, such as "only allowing access between 9:00-18:00"; traffic filtering based on application layer protocols (such as HTTP, DNS); integration with external security systems, such as obtaining threat intelligence from SIEM systems and dynamically updating rules; supporting complex logical conditions, such as "allowing traffic from IP A, and access when the target port is 80 and the request header contains specific fields", etc. Therefore, the scalability and diversity of firewall configuration for business containers can be improved, thereby improving the security of virtualization clusters.
[0075] It's understandable that the Container Network Interface (CNI) plugin is responsible for basic network functions such as allocating IP addresses to Pods, configuring network interfaces, and enabling cross-node communication. Without the CNI plugin, Pods will not be able to obtain network connectivity, causing the Kubernetes cluster to not function properly.
[0076] Here, the underlying CNI interface plug-in is used for basic network connectivity. For example, it is responsible for creating and deleting business container networks and basic network configuration (such as IP allocation and routing settings). It is also used for network interface management to enable network communication between containers and hosts, and between containers. It does not provide network policy enforcement. Specific CNI plug-ins that support network policies can implement fine-grained network access control (such as inter-pod traffic restriction) and security isolation based on Kubernetes NetworkPolicy.
[0077] In some cases, managed Kubernetes services from cloud service providers (such as AWS EKS, Google GKE, or Alibaba Cloud ACK) often come with pre-installed CNI plugins (such as VPC CNI and Calico), eliminating the need for manual installation. When manually deploying a Kubernetes cluster on bare metal or virtual machines, users select and install underlying CNI plugins, such as Flannel and Calico (in BGP mode).
[0078] In some embodiments, / opt / cni is the standard directory for storing CNI plug-ins in Linux systems. Check whether the CNI plug-in executable file exists in the / opt / cni / bin directory. If the executable file exists in the / opt / cni / bin directory, the CNI plug-in is installed.
[0079] In the embodiment of the present disclosure, after the CNI plug-in is installed, the target program can obtain the associated information of the target container group based on the CNI interface, thereby laying the foundation for the subsequent determination of the target configuration items.
[0080] Here, the association information is used to indicate at least various attribute information of the target node where the target container group is located and / or various attribute information of the target container group. For example, the various attribute information of the target container group may include one or more of the following: annotation information of the target container group, first identification information of the target container group, first label information of the target container group, second identification information of the network namespace of the target container group, and second label information of the network namespace of the target container group. The various attribute information of the target node may include one or more of the following: third identification information of the target node and third label information of the target node.
[0081] Exemplarily, the CRI interface of the business container is called based on the identification information ID of the business container to obtain the first identification information and the second identification information. When the first identification information and the second identification information are obtained, the application program interface of the container orchestration engine (i.e., the API interface of Kubernetes) is called to pass the first identification information and the second identification information to Kubernetes to further determine the annotation information and the first label information; at the same time, the API interface of Kubernetes is called again to pass the second identification information to Kubernetes to determine the second label information. Here, the API interface of Kubernetes is used to manage and operate the kuberntes cluster.
[0082] It can be understood that when the configuration file of the virtualization cluster and the associated information of the target container group are obtained, the target configuration entry can be determined based on the configuration file and the associated information; and based on the target configuration entry, the firewall configuration can be performed on the business container in the target container group, thereby improving the accuracy of the firewall configuration and improving the security of the virtualization cluster.
[0083] In some embodiments, a configuration file is used to configure a firewall for a container group in a virtualization cluster. The configuration file may include at least one attribute configuration information and at least one first configuration entry, and one attribute configuration information is associated with at least one first configuration entry. When any attribute information in the associated information matches the corresponding attribute configuration information in the configuration file, the at least one first configuration entry associated with the matching attribute configuration information is determined as a target configuration entry. Based on the target configuration entry, a firewall is configured for the business container in the Pod.
[0084] In other embodiments, when the number of matching attribute configuration information is at least two, based on the levels of each matching attribute configuration information, at least one first configuration entry associated with the attribute configuration information with the highest level is determined as the target configuration entry, thereby improving the accuracy of determining the target configuration entry.
[0085] In an embodiment of the present disclosure, in response to a virtualization cluster creating a target container group, a target program pre-stored in a target node where the target container group is located is called; in response, association information of the target container group is obtained through the target program; wherein the association information includes at least one of the following items: various attribute information of the target node where the target container group is located, and various attribute information of the target container group; a configuration file of the virtualization cluster is obtained, and target configuration items are determined based on the configuration file and the association information; wherein the configuration file is used to perform firewall configuration of the container group; and firewall configuration is performed on the service containers in the target container group based on the target configuration items; wherein the target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration items into firewall rules.
[0086] First, the target program invokes the iptables command-line tool within the target node's operating system, enabling iptables to convert the target configuration entries into firewall rules. This eliminates the need for a CNI plugin that matches the virtualization cluster's resource object NetworkPolicy to convert the target configuration entries. Therefore, even if the CNI plugin doesn't match the NetworkPolicy, the business container can still be accurately configured with a firewall, eliminating the need to install a specific network plugin, improving the efficiency of firewall configuration for business containers.
[0087] Secondly, by adjusting the configuration file, firewall policies can be configured dynamically and uniformly, making firewall configuration more convenient. Furthermore, based on the association between the configuration file and the target container group, the accuracy of identifying target configuration items is improved, thereby improving the precision of firewall configuration for business containers.
[0088] Third, various firewall policies supported by iptables can be implemented on business containers, thereby improving the scalability and diversity of firewall configuration for business containers, and thus improving the security of virtualization clusters.
[0089] In some embodiments, the configuration file includes at least one item of attribute configuration information and at least one first configuration entry, and one item of attribute configuration information is associated with the at least one first configuration entry;
[0090] Based on the configuration files and associated information, determine the target configuration items, including:
[0091] In the case where any item of attribute information in the association information matches corresponding attribute configuration information in the configuration file, at least one first configuration item associated with the matching attribute configuration information is determined as a target configuration item.
[0092] Here, the configuration file includes at least one item of attribute configuration information to indicate the pods that require firewall configuration. Each item of attribute configuration information is associated with at least one first configuration entry, and the first configuration entries associated with each item of attribute configuration information can be the same or different.
[0093] For example, the attribute configuration information is the label app=web for the node, and its associated first configuration entry is "iptables-A CNI-FIREWALL-s 10.10.10.100-j DROP"; the attribute configuration information is the label app=test for the node, and its associated first configuration entry is "iptables-A CNI-FIREWALL-s10.10.10.100-j DROP"; the attribute configuration information is the node name 001, and its associated first configuration entry is "iptables-A CNI-FIREWALL-s10.10.10.100-j DROP"; the attribute configuration information is the node name 002, and its associated first configuration entry is "iptables-A CNI-FIREWALL-s 10.10.10.100-jDROP"; the attribute configuration information is the label app=web for the Namespace, and its associated first configuration entry is "iptables-A CNI-FIREWALL-s 10.10.10.100–j DROP", "iptables-ACNI-FIREWALL-p tcp-dport 8080-j DROP", and "iptables-A CNI-FIREWALL-s192.168.1.0 / 24–j DROP". The attribute configuration information is the Pod label app = web. The first configuration entry associated with it is "iptables-A CNI-FIREWALL-s 10.10.10.100–j DROP", "iptables-ACNI-FIREWALL-ptcp-dport 8080-j DROP", and "iptables-A CNI-FIREWALL-s192.168.1.0 / 24–j DROP". The attribute configuration information is global. The first configuration entry associated with it is "iptables-ACNI-FIREWALL-s10.10.10.100–j DROP", "iptables-ACNI-FIREWALL-p tcp-dport 8080-j DROP", and "iptables-A CNI-FIREWALL-s192.168.1.0 / 24–j DROP".
[0094] It can be understood that in order to improve the accuracy of determining the target configuration entry, for each attribute information in the associated information, the attribute information can be matched with each attribute configuration information in the configuration file respectively; when any attribute information in the associated information matches the corresponding attribute configuration information in the configuration file, it is determined that the current Pod needs to be configured with a firewall, and at least one first configuration entry associated with the matching attribute configuration information can be determined as the target configuration entry.
[0095] Iptables converts the target configuration entries into firewall rules to configure the firewall for the Pod's business container, thereby reducing invalid configurations and improving the efficiency of firewall configuration for business containers.
[0096] Exemplarily, when one of the attribute information in the association information is the label of the Pod, and the label of the Pod is app=web, and the attribute configuration information in the configuration file is the label of the Pod, and the label of the Pod is app=web, it is determined that the attribute information in the association information matches the attribute configuration information, and the first configuration entries associated with the attribute configuration information, "iptables-ACNI-FIREWALL-s 10.10.10.100–j DROP", "iptables-A CNI-FIREWALL-p tcp-dport8080-j DROP", and "iptables-ACNI-FIREWALL-s 192.168.1.0 / 24–j DROP", are all determined as target configuration entries.
[0097] In an embodiment of the present disclosure, when any attribute information in the associated information matches the corresponding attribute configuration information in the configuration file, at least one first configuration entry associated with the matching attribute configuration information is determined as the target configuration entry, thereby reducing the situation of invalid configuration, thereby improving the accuracy of firewall configuration and improving the security of the virtualization cluster.
[0098] In some embodiments, when any attribute information in the association information matches corresponding attribute configuration information in the configuration file, determining at least one first configuration item associated with the matching attribute configuration information as a target configuration item includes:
[0099] For each attribute information, determine whether the attribute information matches the corresponding attribute configuration information in the configuration file;
[0100] When the number of matched attribute configuration information is one item, determining at least one first configuration item associated with the matched attribute configuration information as a target configuration item;
[0101] When there are at least two matching attribute configuration information, based on the levels of the respective matching attribute configuration information, determining at least one first configuration item associated with the attribute configuration information with the highest level as the target configuration item;
[0102] Among them, different attribute configuration information has different levels.
[0103] Here, for each item of attribute information, a determination is made as to whether the attribute information matches the corresponding attribute configuration information in the configuration file. For example, a string-based method, a vector-based method, or a deep learning-based method can be used to obtain the matching result between the attribute information and the corresponding attribute configuration information in the configuration file, although this disclosure is not limited to this.
[0104] In some embodiments, attribute information is converted into single characters required for attribute configuration information by means of Levenshtein distance for editing operations, and based on the number of editing operations, a matching result between the attribute information and the corresponding attribute configuration information in the configuration file can be determined, wherein the editing operation at least includes inserting a character, deleting a character, or replacing a character. When the number of editing operations is less than a preset threshold, the smaller the edit distance, the higher the matching degree of the two character strings, and the attribute information is determined to match the corresponding attribute configuration information in the configuration file; and when the number of editing operations is greater than or equal to the preset threshold, the larger the edit distance, the lower the matching degree of the two character strings, and the attribute information is determined to not match the corresponding attribute configuration information in the configuration file.
[0105] In other embodiments, the attribute information and the attribute configuration information are converted into TF-IDF vectors by using TF-IDF vectors, and the cosine value of the angle between the two TF-IDF vectors in the vector space is calculated to further determine the matching result between the attribute information and the corresponding attribute configuration information in the configuration file. For example, when the cosine value is closer to 1, it indicates that the directions of the two vectors are closer, that is, it is determined that the attribute information matches the corresponding attribute configuration information in the configuration file; and when the cosine value is closer to 0, it indicates that the directions of the two vectors are perpendicular, that is, it is determined that the attribute information does not match the corresponding attribute configuration information in the configuration file.
[0106] Here, the larger the value corresponding to the level of the attribute configuration information, the higher the level of the attribute configuration information. The attribute configuration information can include: global, node label, node name, namespace label, namespace name, and Pod label. For example, the global level is 0, which means that the container firewall of all Pod services on the target node will be configured. The node label level is 1, which means that if the attribute information includes the node label, the container firewall of the current Pod will be configured. The node name level is 2, which means that if the attribute information includes the node name, the container firewall of the current Pod will be configured. The namespace label level is 3, which means that if the attribute information includes the namespace label, the container firewall of the current Pod will be configured. The namespace name level is 4, which means that if the attribute information includes the namespace name, the container firewall of the current Pod will be configured. The Pod label level is 5, which means that if the attribute information includes the Pod label, the container firewall of the current Pod will be configured.
[0107] It is understandable that, considering that the first configuration items associated with attribute configuration information of different levels may be different, when the number of matching attribute configuration information is at least two items, at least one first configuration item associated with the attribute configuration information of the highest level can be determined as the target configuration item, thereby improving the accuracy of the firewall configuration of the business container.
[0108] In the embodiment of the present disclosure, the number of matching attribute configuration information is first determined, and then the target configuration item is determined based on the number of matching attribute configuration information, thereby improving the accuracy of determining the target configuration item and further improving the accuracy of firewall configuration for the business container.
[0109] In some embodiments, the association information includes at least one of the following: annotation information of the target container group, information classifying or identifying the target container group or the target node;
[0110] The method further includes:
[0111] When the association information includes annotation information of the target container group and at least one second configuration entry exists in the annotation information, the at least one second configuration entry is determined as the target configuration entry.
[0112] Here, in Kubernetes, annotations are a type of metadata for Pods, used to store non-identifying additional information, such as deployment tool version information, Git repository address information, debugging information, or custom metadata.
[0113] In some embodiments, metadata.annotations is part of the metadata of the Pod and is used to store non-identifying additional information. The metadata.annotations field can be used to store customized second configuration entries. For example, firewall.rule.ingress: defines inbound rules; firewall.rule.egress: defines outbound rules; firewall.rule.description: is used to record the purpose of the rule. For example, firewall.rule.ingress: allow-tcp-80, which means allowing inbound traffic on tcp port 80; firewall.rule.egress: deny all, which means denying all outbound traffic.
[0114] It is understood that after obtaining the Pod's annotation information, the Pod's annotation information can be parsed to determine whether the annotation information contains at least one second configuration entry. Considering that the level of annotation information is higher than the level of each attribute configuration information in the configuration file, to improve the accuracy and efficiency of firewall configuration, if it is determined that the annotation information contains a second configuration entry, the second configuration entry is converted into a firewall rule to configure the firewall for the business container. If it is determined that the annotation information does not contain a second configuration entry, the number of attribute configuration information that matches the attribute information is determined, and based on this number, the target configuration entry is determined.
[0115] Here, in addition to the annotation information of the target container group, the association information also includes information for classifying or identifying the target container group and the target node. For example, the association information includes at least one of the following: first identification information of the target container group, first label information of the target container group, second identification information of the network namespace of the target container group, second label information of the network namespace of the target container group, third identification information of the target node, and third label information of the target node.
[0116] In some embodiments, when the attribute configuration information in the configuration file is identification information of the target container group, it is determined whether the identification information matches the first identification information; when the attribute configuration information in the configuration file is label information of the target container group, it is determined whether the label information matches the first label information; when the attribute configuration information in the configuration file is identification information of the network namespace, it is determined whether the identification information matches the second identification information; when the attribute configuration information in the configuration file is label information of the target container group, it is determined whether the label information matches the third label information; when the attribute configuration information in the configuration file is identification information of the target node, it is determined whether the identification information matches the third identification information; when the attribute configuration information in the configuration file is label information of the target node, it is determined whether the label information matches the third label information.
[0117] After matching the above information, the number of matching attribute configuration information is determined; when the number of matching attribute configuration information is one, at least one first configuration entry associated with the matching attribute configuration information is determined as the target configuration entry; when the number of matching attribute configuration information is at least two, based on the levels of each matching attribute configuration information, at least one first configuration entry associated with the attribute configuration information with the highest level is determined as the target configuration entry.
[0118] In the embodiments of the present disclosure, on the one hand, when the associated information includes Pod annotation information and there is a second configuration entry in the Pod annotation information, the second configuration entry pre-stored in the Pod annotation information can be parsed, and the firewall configuration of the business container can be performed according to the second configuration entry, thereby meeting the more fine-grained control requirements in certain scenarios and the consistency requirements of firewall rules of multiple clusters; on the other hand, when the associated information does not include Pod annotation information, or there is no second configuration entry in the Pod annotation information, firewall hierarchical configuration can also be performed based on the global, Node name, Node label, Namespace name, Namespce label and Pod label, which is beneficial to improving the security of the cluster.
[0119] In some embodiments, the information for classifying or identifying the target container group includes at least one of the following: first identification information of the target container group, first label information of the target container group, second identification information of a network namespace of the target container group, and second label information of the network namespace of the target container group;
[0120] Obtain the associated information of the target container group through the target program, including:
[0121] Obtaining, through the target program, business container identification information corresponding to the target container group based on the first network interface of the business container, and obtaining first identification information and second identification information based on the business container identification information and the operation interface of the business container; wherein the first network interface is used to manage the network configuration of the business container, and the operation interface is used to manage the lifecycle of the business container;
[0122] Determining annotation information and first tag information based on the first identification information and the second identification information;
[0123] Based on the second identification information, the second label information is determined. Here, the operation interface is the business container runtime interface (Container Runtime Interface, CRI), which is a set of standardized interfaces defined by Kubernetes for implementing interaction between the container runtime and the Kubernetes cluster. The CRI interface provides a remote procedure call API through a preset protocol (for example, Google Remote Procedure Call, gRPC), which standardizes the lifecycle management of business containers, including functions such as creating, starting, stopping, and deleting business containers.
[0124] In some embodiments, the target program can obtain attribute information of the business container, such as identification information of the business container, based on the CNI interface.
[0125] Here, based on the business container's identification information, the CRI interface of the business container is called to obtain the first identification information and the second identification information. After obtaining the first identification information and the second identification information, the Kubernetes API interface is called to pass the first identification information and the second identification information to Kubernetes to determine the annotation information and the first label information; the Kubernetes API interface is called to pass the second identification information to Kubernetes to determine the second label information.
[0126] In the embodiment of the present disclosure, based on the CNI interface of the business container, the business container identification information corresponding to the target container group can be obtained; by calling the CRI interface, the API interface of Kubernetes and the business container identification information, the first identification information of the target container group, the first label information of the target container group, the second identification information of the network namespace of the target container group and the second label information of the network namespace of the target container group can be determined, thereby improving the accuracy and efficiency of determining the above attribute information, thereby improving the accuracy of firewall configuration.
[0127] In some embodiments, the information for classifying or identifying the target node includes at least one of the following: third identification information of the target node and third label information of the target node;
[0128] Obtain the target container group's associated information through the target program, including:
[0129] Determining, by the target program, third identification information based on an environment variable of the operating system;
[0130] Based on the third identification information, the third tag information is determined. Here, operating system environment variables are used to store key-value pairs of system or application configuration information. These are set by the operating system or application and are read and used during the execution of the business container. Environment variables can influence process behavior, such as specifying paths, storing configuration information, or providing runtime parameters.
[0131] In some embodiments, hostname is a commonly used environment variable used to store third identification information of the target node. The third identification information can be determined by reading the / etc / hostname file.
[0132] In the embodiment of the present disclosure, when the third identification information is obtained, the third label information can be determined by calling the API interface of Kubernetes to transmit the third identification information to Kubernetes.
[0133] In the embodiment of the present disclosure, through the target program, based on the environment variables of the operating system, the third identification information of the target node and the third label information of the target node can be determined, thereby improving the accuracy and efficiency of determining the third identification information and the third label information, thereby improving the accuracy of the firewall configuration.
[0134] In some embodiments, the method further comprises:
[0135] Obtaining, through the target program, a container network configuration path of the business container corresponding to the target container group based on a first network interface of the business container; wherein the first network interface is used to manage the network configuration of the business container;
[0136] Based on the container network configuration path, determine a second network interface used by the network namespace of the target container group; wherein the second network interface is used to manage the communication capability of the target container group with the external network;
[0137] Based on the target configuration items, firewall configuration is performed on the business containers in the target container group, including:
[0138] Based on the target configuration entry, firewall configuration is performed on the second network interface to implement firewall configuration on the service container in the target container group.
[0139] In the disclosed embodiment, the first network interface is a CNI interface. When a service container is running and a network needs to be configured for the service container, the CNI interface is called to pass information such as the service container's network namespace path, CNI configuration file path, and service container ID.
[0140] Here, after determining the network namespace path of the service container, the Linux tool nsenter can be used to enter the network namespace, and then the second network interface used by the network namespace can be determined using a preset instruction. For example, the preset instruction can be an ip a or ifconfig command.
[0141] In some embodiments, when business containers within a target container group share a second network interface, if the association information includes annotation information for the target container group and at least one second configuration entry exists within the annotation information, a firewall configuration is performed on the second network interface based on the at least one second configuration entry. If the association information does not include annotation information for the target container group, or if at least one second configuration entry does not exist within the annotation information, the number of matching attribute configuration information is determined; if the number of matching attribute configuration information is one, a firewall configuration is performed on the second network interface based on at least one first configuration entry associated with the matching attribute configuration information. In other embodiments, the network namespace provides isolation and flexibility, allowing each business container to run in an independent network namespace, have an independent network stack, and configure a different network environment based on business needs. In addition, the second network interface used by the network namespace of each business container can be different. Therefore, to improve the accuracy of firewall configuration for the business containers of a Pod, for each business container, the container network configuration path of the business container is first determined, and then the second network interface used by the network namespace is determined.
[0142] Exemplarily, the business containers of a Pod include container A and container B, the second network interface of container A is eth0@if123, and the second network interface of container B is eth0@if456; when the association information includes annotation information of the target container group and there is at least one second configuration entry in the annotation information, firewall configuration is performed on eth0@if123 and eth0@if456 respectively based on the at least one second configuration entry. When the association information does not include annotation information of the target container group, or there is no at least one second configuration entry in the annotation information, the number of matching attribute configuration information is determined; when the number of matching attribute configuration information is one, firewall configuration is performed on eth0@if123 and eth0@if456 respectively based on at least one first configuration entry associated with the matching attribute configuration information; when the number of matching attribute configuration information is at least two, firewall configuration is performed on eth0@if123 and eth0@if456 respectively based on at least one first configuration entry associated with the highest-level attribute configuration information.
[0143] Here, performing firewall configuration on the second network interface may be understood as executing the firewall rule corresponding to the first configuration entry or the firewall rule corresponding to the second configuration entry on the second network interface.
[0144] In the disclosed embodiment, the target program first determines the container network configuration path for each service container corresponding to the target container group, then determines the second network interface used by the network namespace, and then performs firewall configuration on the second network interface to implement firewall configuration for the service containers in the target container group. This reduces the possibility of missed configurations for service containers, improves the accuracy of service container firewall configuration, and thus enhances the security of the virtualization cluster.
[0145] Based on this, the implementation process of the security management method described in the above embodiment in an actual application scenario is specifically described below. Figure 4 This is a schematic diagram of the architecture of a security management system provided by the embodiment of the present application. Figure 2 ,like Figure 4 As shown, the security management device provided in the embodiment of the present application may include the following modules:
[0146] Module 401 is the application programming interface of the virtualization cluster, that is, the API interface of Kubernetes, which is used to manage and operate the kuberntes cluster and obtain the associated information of the target container group. For example, it obtains the annotation information of the target container group, the first identification information of the target container group, the first label information of the target container group, the second identification information of the network namespace of the target container group, and the second label information of the network namespace of the target container group.
[0147] Module 402 is a configuration file of the virtualization cluster, which is used to configure the firewall of the container group.
[0148] Module 403 is a target node, which is used to provide CPU, memory, storage and network resources for use by the target container group Pod (i.e., 404 in the figure).
[0149] Module 404 is the target container group Pod, which is used for application encapsulation, lifecycle management, and resource allocation.
[0150] Module 405 is a business container, which directly runs the business container of the application in the target container group Pod (i.e., 404 in the figure). The business container with the business program is deployed and is used to execute the application, check the application status, and output logs.
[0151] Module 406 is a firewall Pod, which is used to ensure that the target node (i.e., 403 in the figure) has a unified security protection capability to avoid security vulnerabilities caused by the lack of node protection.
[0152] Module 407 is a target program used to call a command line tool within the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule; the target configuration entry is determined based on key information of the configuration file (i.e., Figure 402) and the target container group (i.e., Figure 404).
[0153] Module 408 is a mount directory, / opt / cni / bin / , to which the firewall Pod (shown as 406 ) is mounted during startup, so that the target program (shown as 407 ) can be chain-called by the CNI on the target node.
[0154] Module 409 is a communication path, unix: / / / run / containerd / containerd.sock. When the target program (ie, 407 in the figure) is called by the CNI, the target program communicates with the CRI through the communication path to obtain the container information of the business container (ie, 405 in the figure).
[0155] Module 410 is the container network configuration path, / var / run / netns / cni-x. Through the target program (i.e., Figure 407), based on the first network interface of the business container, the container network configuration path of the business container corresponding to the target container group is obtained. The container network namespace is entered through the container network configuration path, and the second network interface used for the container network naming is determined to perform firewall configuration on the second network interface, thereby implementing firewall configuration for the business containers in the target container group.
[0156] In an embodiment of the present disclosure, in response to a virtualization cluster creating a target container group, a target program pre-stored in a target node where the target container group is located is called; in response, association information of the target container group is obtained through the target program; wherein the association information includes at least one of the following items: various attribute information of the target node where the target container group is located, and various attribute information of the target container group; a configuration file of the virtualization cluster is obtained, and target configuration items are determined based on the configuration file and the association information; wherein the configuration file is used to perform firewall configuration of the container group; and firewall configuration is performed on the service containers in the target container group based on the target configuration items; wherein the target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration items into firewall rules.
[0157] First, the target program invokes the iptables command-line tool within the target node's operating system, enabling iptables to convert the target configuration entries into firewall rules. This eliminates the need for a CNI plugin that matches the virtualization cluster's resource object NetworkPolicy to convert the target configuration entries. Therefore, even if the CNI plugin doesn't match the NetworkPolicy, the business container can still be accurately configured with a firewall, eliminating the need to install a specific network plugin, improving the efficiency of firewall configuration for business containers.
[0158] Secondly, by adjusting the configuration file, firewall policies can be configured dynamically and uniformly, making firewall configuration more convenient. Furthermore, based on the association between the configuration file and the target container group, the accuracy of identifying target configuration items is improved, thereby improving the precision of firewall configuration for business containers.
[0159] Third, various firewall policies supported by iptables can be implemented on business containers, thereby improving the scalability and diversity of firewall configuration for business containers, and thus improving the security of virtualization clusters.
[0160] The following continues to describe the exemplary structure of the security management device 255 provided in the application embodiment implemented as a software module. In some embodiments, such as Figure 2As shown, the software modules stored in the security management device 255 of the memory 250 may include:
[0161] A calling module 2551 is configured to call a target program pre-stored in a target node where the target container group is located in response to the virtualization cluster creating the target container group;
[0162] A first acquisition module 2552 is configured to acquire, through the target program, association information of the target container group; wherein the association information includes at least one of the following: various attribute information of the target node where the target container group is located, and various attribute information of the target container group;
[0163] A first determination module 2553 is configured to obtain a configuration file of the virtualization cluster and determine a target configuration item based on the configuration file and the association information; wherein the configuration file is used to configure a firewall for the container group;
[0164] A first configuration module 2554 is configured to perform firewall configuration on the business container in the target container group based on the target configuration entry;
[0165] The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
[0166] In some embodiments, the configuration file includes at least one item of attribute configuration information and at least one first configuration entry, and one item of attribute configuration information is associated with the at least one first configuration entry;
[0167] The first configuration module 2554 is specifically configured as follows:
[0168] In the case where any item of attribute information in the association information matches corresponding attribute configuration information in the configuration file, at least one first configuration item associated with the matching attribute configuration information is determined as the target configuration item.
[0169] In some embodiments, the first configuration module 2554 is further configured to:
[0170] For each item of attribute information, determining whether the attribute information matches the corresponding attribute configuration information in the configuration file;
[0171] When the number of matched attribute configuration information is one item, determining at least one first configuration item associated with the matched attribute configuration information as the target configuration item;
[0172] In a case where a number of matched attribute configuration information is at least two, based on levels of each matched attribute configuration information, at least one first configuration item associated with an attribute configuration information of a highest level is determined as the target configuration item;
[0173] wherein the levels of different attribute configuration information are different.
[0174] In some embodiments, the association information comprises at least one of the following: annotation information of the target container group, information for classifying or identifying the target container group and the target node;
[0175] The security management apparatus 255 further comprises:
[0176] The second configuration module is configured to, in a case where the association information comprises annotation information of the target container group and at least one second configuration item exists in the annotation information, determine the at least one second configuration item as the target configuration item.
[0177] In some embodiments, the information for classifying or identifying the target container group comprises at least one of the following: first identification information of the target container group, first label information of the target container group, second identification information of a network namespace of the target container group, and second label information of the network namespace of the target container group.
[0178] The first obtaining module 2552 is specifically configured to:
[0179] The target program is used to obtain, based on a first network interface of a service container, service container identification information corresponding to the target container group, and based on the service container identification information and a running interface of the service container, the first identification information and the second identification information, wherein the first network interface is used to manage network configuration of the service container, and the running interface is used to manage a life cycle of the service container.
[0180] The first identification information and the second identification information are used to determine the annotation information and the first label information.
[0181] The second identification information is used to determine the second label information.
[0182] In some embodiments, the information for classifying or identifying the target node comprises at least one of the following: third identification information of the target node and third label information of the target node.
[0183] The first obtaining module 2552 is further configured to:
[0184] The third identification information is determined based on an environment variable of the operating system through the target program.
[0185] The third label information is determined based on the third identification information.
[0186] In some embodiments, the security management apparatus 255 further includes:
[0187] The second obtaining module is configured to obtain, through the target program, a container network configuration path of a service container corresponding to the target container group based on a first network interface of the service container, where the first network interface is used to manage network configuration of the service container.
[0188] The second determining module is configured to determine a second network interface used by a network namespace of the target container group based on the container network configuration path, where the second network interface is used to manage communication capability of the target container group with an external network.
[0189] The first configuration module 2554 is specifically configured to:
[0190] The target container group is configured based on the target configuration item by performing firewall configuration on the second network interface.
[0191] It should be noted that the description of the security management apparatus in the embodiments of the present application is similar to the description of the security management method described above, and has similar beneficial effects to the method embodiments, and thus will not be described here.
[0192] The embodiments of the present application provide a computer program product or a computer program, which includes computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to enable the computer device to perform the security management method described above in the embodiments of the present application.
[0193] The embodiments of the present application provide a computer readable storage medium storing executable instructions, wherein the computer program or executable instructions are stored, and when the computer program or executable instructions are executed by a processor, the processor will execute the security management method provided by the embodiments of the present application, for example, the security management method as shown in Figure 3 .
[0194] In some embodiments, the computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM memory, etc. It can also be various devices including one or any combination of the above memories.
[0195] In some embodiments, executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0196] As an example, executable instructions may, but need not, correspond to a file in a file system, may be stored as part of a file that stores other programs or data, such as in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions).
[0197] By way of example, executable instructions may be deployed to be executed on one computing device, or on multiple computing devices at one site, or on multiple computing devices distributed across multiple sites and interconnected by a communication network.
[0198] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are included in the scope of protection of the present application.
Claims
1. A security management method for a virtualization cluster, characterized in that: The method comprises: In response to the virtualization cluster creating a target container group, calling a target program pre-stored in a target node where the target container group is located; Acquire association information of the target container group through the target program; wherein the association information includes at least one of the following items: various attribute information of the target node where the target container group is located, and various attribute information of the target container group; Obtaining a configuration file of the virtualization cluster, and determining a target configuration item based on the configuration file and the associated information; wherein the configuration file is used to configure a firewall for the container group; Performing firewall configuration on the service container in the target container group based on the target configuration entry; The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
2. The method according to claim 1, characterized in that The configuration file includes at least one item of attribute configuration information and at least one first configuration entry, and one item of attribute configuration information is associated with at least one first configuration entry; The determining of a target configuration item based on the configuration file and the association information includes: In the case where any item of attribute information in the association information matches corresponding attribute configuration information in the configuration file, at least one first configuration item associated with the matching attribute configuration information is determined as the target configuration item.
3. The method according to claim 2, characterized in that When any one of the attribute information in the association information matches the corresponding attribute configuration information in the configuration file, determining at least one first configuration item associated with the matching attribute configuration information as the target configuration item includes: For each item of attribute information, determining whether the attribute information matches the corresponding attribute configuration information in the configuration file; When the number of matched attribute configuration information is one item, determining at least one first configuration item associated with the matched attribute configuration information as the target configuration item; When there are at least two matching attribute configuration information, based on the levels of the respective matching attribute configuration information, determining at least one first configuration item associated with the attribute configuration information with the highest level as the target configuration item; Among them, different attribute configuration information has different levels.
4. The method according to claim 3, characterized in that The association information includes at least one of the following: annotation information of the target container group, information for classifying or identifying the target container group and the target node; The method further comprises: When the association information includes annotation information of the target container group and at least one second configuration entry exists in the annotation information, the at least one second configuration entry is determined as the target configuration entry.
5. The method according to claim 4, characterized in that The information for classifying or identifying the target container group includes at least one of the following: first identification information of the target container group, first label information of the target container group, second identification information of the network namespace of the target container group, and second label information of the network namespace of the target container group; The acquiring, through the target program, the associated information of the target container group includes: Obtaining, by the target program, business container identification information corresponding to the target container group based on a first network interface of the business container, and obtaining the first identification information and the second identification information based on the business container identification information and an operation interface of the business container; wherein the first network interface is used to manage the network configuration of the business container, and the operation interface is used to manage the lifecycle of the business container; determining the annotation information and the first tag information based on the first identification information and the second identification information; The second tag information is determined based on the second identification information.
6. The method according to claim 4, characterized in that The information for classifying or identifying the target node includes at least one of the following: third identification information of the target node and third label information of the target node; The acquiring, through the target program, the associated information of the target container group includes: determining, by the target program, the third identification information based on an environment variable of the operating system; The third tag information is determined based on the third identification information.
7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Obtaining, by the target program, a container network configuration path of the business container corresponding to the target container group based on a first network interface of the business container; wherein the first network interface is used to manage the network configuration of the business container; Determine, based on the container network configuration path, a second network interface used by the network namespace of the target container group; wherein the second network interface is used to manage the communication capability between the target container group and the external network; The performing firewall configuration on the service container in the target container group based on the target configuration entry includes: Based on the target configuration entry, firewall configuration is performed on the second network interface to implement firewall configuration for the service container in the target container group.
8. A security management device, characterized in that: The device comprises: A calling module is configured to call a target program pre-stored in a target node where the target container group is located in response to the virtualization cluster creating the target container group; a first acquisition module configured to acquire, through the target program, association information of the target container group; wherein the association information includes at least one of the following: various attribute information of the target node where the target container group is located, and various attribute information of the target container group; A first determination module is configured to obtain a configuration file of the virtualization cluster and determine a target configuration item based on the configuration file and the association information; wherein the configuration file is used to configure a firewall for the container group; a first configuration module configured to perform firewall configuration on the service container in the target container group based on the target configuration entry; The target program is used to call a command line tool in the operating system of the target node, and the command line tool is used to convert the target configuration entry into a firewall rule.
9. An electronic device, characterized in that: include: Memory for storing computer programs or executable instructions; A processor, configured to implement the method according to any one of claims 1 to 7 when executing the computer program or the executable instructions stored in the memory.
10. A computer-readable storage medium having a computer program or executable instructions stored thereon, characterized in that: When the computer program or the executable instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.