Heterogeneous mirror image construction method and device based on multi-client environment

Through the container image construction method of dynamic adaptation and security compliance correction, the problems of low image construction efficiency and insufficient security caused by the heterogeneity of multi-customer IT infrastructure are solved, and efficient and secure image construction and distribution are achieved.

CN120803602APending Publication Date: 2025-10-17ACCOUNTING CENT OF CHINA AVIATION LTD CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510776772.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

In the distributed IT information systems of the civil aviation sector, due to the heterogeneity of multi-customer IT infrastructure, traditional container image building methods face problems such as environmental fragmentation, high manual adaptation costs, image redundancy, low security detection coverage, and low cross-node building efficiency.

Method used

By generating a build instruction set, dynamically adapting the base image, building the container image using the OCI standard, performing security compliance corrections and image layer reduction, combining the global layered cache repository to share the common layer, and supporting custom environment differences, the automated building and security compliance of the image can be achieved.

Benefits of technology

The efficiency and quality of image building in multi-customer heterogeneous environments have been significantly improved, with cross-airport build time shortened by 65%, the duplicate build rate reduced to 10%, the image size reduced by 72%, and the security and compliance detection coverage reaching 100%, reducing labor maintenance costs and storage and transmission costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120803602A_ABST
    Figure CN120803602A_ABST
Patent Text Reader

Abstract

The invention discloses a heterogeneous mirror image construction method and device based on a multi-client environment. The method comprises the following steps: generating a construction instruction set according to software and hardware environment parameter information of an airport information system; based on an underlying OCI standard, a container mirror image is constructed by utilizing the basic mirror image, the dependency registration instruction and the tool chain parameters; in the construction process, a public layer is shared through a global layered cache warehouse, and introduction of customer-defined environment differences is supported; performing safety compliance correction on the container mirror image to obtain a corrected container mirror image; the security compliance correction comprises vulnerability scanning and repairing, sensitive information identification and desensitization processing, and blocking of instructions which do not accord with preset airport information system security requirements; performing mirror image layer reduction on the corrected container mirror image by using a mirror image compression tool to obtain a layer-reduced container mirror image; and carrying out multi-warehouse distribution on the container mirror image after layer reduction. According to the invention, the efficiency and quality of mirror image construction in a multi-client heterogeneous environment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of container image technology, and in particular to a heterogeneous image construction method and device based on a multi-client environment. BACKGROUND

[0002] This section is intended to provide background or context to the embodiments of the application recited in the claims. The description herein does not constitute admission that the subject matter disclosed herein is prior art to the present application.

[0003] In the field of civil aviation, the heterogeneity of multi-client IT infrastructure in distributed IT information systems poses significant challenges to traditional container image construction methods: environmental fragmentation, operating system heterogeneity, different clients using different operating system versions, and differences in kernel versions. For example, old branch airports commonly run 3.10 kernels, while hub airports have upgraded to 5.15 kernels; network policy isolation, 80% of airports restrict public network access and require connection to enterprise-level private image repositories through internal private networks; software branch customization, there are more than 3 customized branches of the same business system.

[0004] Traditional image construction has the following defects: the image construction process definition text needs to be written for each airport, and manual adaptation is costly; image redundancy is common, with a volume of 150%-200% more than required; security detection is post-processed, with a vulnerability coverage rate of <60%; cross-node construction efficiency is low, with a repetition rate of up to 75%, etc. SUMMARY

[0005] The embodiments of the present application provide a heterogeneous image construction method based on a multi-client environment to improve the efficiency and quality of image construction in a multi-client heterogeneous environment. The method comprises:

[0006] Generating a construction instruction set according to the software and hardware environment parameter information of the client airport information system; the construction instruction set includes basic image requirement instructions, dependency registration instructions, and tool chain parameters;

[0007] Obtaining a basic image based on the basic image requirement instructions;

[0008] Based on the underlying OCI (Open Container Initiative) standard, the container image is constructed using the basic image, dependency registration instructions, and tool chain parameters; during the construction process, the public layer is shared through a global layered cache repository, and the introduction of customer-defined environmental differences is supported;

[0009] Performing security compliance correction on the container image to obtain a corrected container image; the security compliance correction includes vulnerability scanning and repair, sensitive information identification and desensitization processing, and blocking of instructions that do not meet the preset airport information system security requirements;

[0010] The layer-reduced container image is distributed to multiple warehouses.

[0011] The layer-reduced container image is distributed to multiple warehouses.

[0012] The embodiment of the application further provides a heterogeneous image construction device based on a multi-client environment, to improve the efficiency and quality of image construction in a multi-client heterogeneous environment, the device comprising:

[0013] An environment configuration analysis module is configured to generate a construction instruction set according to the software and hardware environment parameter information of the client information system; the construction instruction set comprises a basic image requirement instruction, a dependency registration instruction, and a tool chain parameter;

[0014] A basic image dynamic adaptation module is configured to obtain a basic image based on the basic image requirement instruction;

[0015] A heterogeneous perception construction module is configured to construct a container image based on the bottom-layer OCI standard, using the basic image, the dependency registration instruction, and the tool chain parameter; during the construction process, a global layered cache warehouse is shared to support the introduction of customer-defined environment differences;

[0016] A security compliance module is configured to correct a container image for security compliance, to obtain a corrected container image; the security compliance correction comprises vulnerability scanning and repair, sensitive information identification and desensitization processing, and blocking of instructions that do not meet the preset information system security requirements;

[0017] A layered optimization module is configured to use an image compression tool to perform layer reduction on the corrected container image, to obtain a layer-reduced container image;

[0018] A cross-airport image distribution module is configured to distribute the layer-reduced container image to multiple warehouses.

[0019] The embodiment of the application further provides a computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the above-mentioned heterogeneous image construction method based on a multi-client environment when executing the computer program.

[0020] The embodiment of the application further provides a computer-readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the above-mentioned heterogeneous image construction method based on a multi-client environment.

[0021] The embodiment of the application further provides a computer program product, which comprises a computer program, wherein the computer program is executed by a processor to implement the above-mentioned heterogeneous image construction method based on a multi-client environment.

[0022] The embodiment of the present application significantly improves the efficiency and quality of image construction in a multi-client heterogeneous environment through dynamic adaptation, public layer sharing, mirror layer reduction, security embedding and other technologies. The construction instruction set is generated according to the software and hardware environment parameter information of the client airport information system, and more than 15 kinds of heterogeneous environments are automatically adapted, covering OS, kernel, network strategy, etc. During the construction process, the public layer is shared through the global layered cache warehouse, the customer's custom environment difference is supported, the cross-airport construction time is shortened by 65%, the repeated construction rate is reduced from 75% to less than 10%, and the manpower maintenance cost is reduced by 58%; the security compliance detection rate of high-risk vulnerabilities is improved by 40%, the security compliance detection coverage rate is 100%, and the risk response time is shortened from hours to minutes; the image size is reduced by an average of 72% (such as Nginx image from 1.2GB to 350MB), and the storage and transmission cost is reduced by 60%; the industry-specific problems such as airport private network and old kernel compatibility are solved, multi-architecture automatic generation and cross-warehouse distribution are supported, the technology can be migrated to multi-node heterogeneous scenarios such as logistics and transportation, and the standardization and automation transformation of distributed IT system containerization are promoted, which has advanced technology and industrial application value. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. In the drawings:

[0024] Figure 1 The flowchart of the heterogeneous image construction method based on the multi-client environment in the embodiment of the present application;

[0025] Figure 2 The specific example diagram of the heterogeneous image construction method based on the multi-client environment in the embodiment of the present application;

[0026] Figure 3 The specific example diagram of the heterogeneous image construction method based on the multi-client environment in the embodiment of the present application;

[0027] Figure 4 The schematic diagram of the heterogeneous image construction device based on the multi-client environment in the embodiment of the present application;

[0028] Figure 5 The schematic diagram of the computer device in the embodiment of the present application. DETAILED DESCRIPTION

[0029] For the purposes of the embodiments of the present application, the technical solutions and advantages, the embodiments of the present application are further described in detail below with reference to the drawings. Herein, the illustrative embodiments of the present application and their descriptions are used to explain the present application, but not as a limitation of the present application.

[0030] The acquisition, transmission, storage, use, processing, etc. of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0031] In the distributed IT system in the field of civil aviation, the heterogeneity of the multi-client IT infrastructure leads to significant challenges for the traditional container image construction method: environment fragmentation problem, operating system heterogeneity, different clients use different operating systems, different kernel versions, and the kernel versions commonly run by old branch airports are different from the kernel versions of hub airports; network policy isolation, 80% of the airports limit public network access and need to connect enterprise-level private image repositories through internal private networks; software branch customization, there are more than 3 customized branches of the same business system.

[0032] In the multi-client heterogeneous IT environment, the traditional image construction has the following defects:

[0033] (1) High cost of manual adaptation, 2-3 days of manual adjustment are required for single environment change, and the version online time is delayed in many cases, affecting the online timeliness;

[0034] (2) Serious image redundancy, the average size of the general image exceeds the running demand by 150%-200%;

[0035] (3) There are high-risk vulnerabilities in the airport images that have not been repaired, and 20% contain sensitive information such as hard-coded passwords;

[0036] (4) Low construction efficiency, repeated construction leads to resource waste, single-airport image construction takes an average of 45 minutes, and cross-airport synchronization requires an additional 2 hours;

[0037] (5) Existing tools only support static multi-stage construction, which cannot meet the requirements of high availability and rapid deployment of civil aviation systems.

[0038] To solve the defects of the prior art, the embodiments of the present application provide an automatic construction method, which dynamically generates an adaptation strategy, uses a tool (APKO) for constructing a container image to declare a minimized image, integrates a container image and a file system vulnerability scanning tool to realize safe blocking of the construction process, and shares a cross-airport public layer with the help of a global layered cache. Compared with the traditional scheme, the image size is reduced by an average of 72%, the construction time is shortened by 65%, the safety and compliance detection coverage reaches 100%, and the image construction problem in the multi-airport heterogeneous environment is solved, which significantly improves the efficiency and safety.

[0039] Figure 1A flowchart of a heterogeneous image construction method based on a multi-client environment in an embodiment of the present application is shown in Figure Figure 1 The method comprises the following steps:

[0040] Step 101: generating a construction instruction set according to the software and hardware environment parameter information of the client airport information system; the construction instruction set comprises a basic image requirement instruction, a dependency registration instruction, and a tool chain parameter.

[0041] Step 102: obtaining a basic image based on the basic image requirement instruction.

[0042] Step 103: constructing a container image based on the OCI standard, using the basic image, the dependency registration instruction, and the tool chain parameter; during the construction process, a global layered cache repository is shared to support the introduction of customer-defined environment differences.

[0043] Step 104: performing security compliance correction on the container image to obtain a corrected container image; the security compliance correction comprises vulnerability scanning and repair, sensitive information identification and desensitization processing, and blocking instructions that do not meet the preset airport information system security requirements.

[0044] Step 105: using an image compression tool to reduce the image layers of the corrected container image to obtain a container image after layer reduction.

[0045] Step 106: distributing the container image after layer reduction to multiple repositories.

[0046] The following specifically describes the heterogeneous image construction method based on a multi-client environment in an embodiment of the present application.

[0047] In step 101, a construction instruction set is generated according to the software and hardware environment parameter information of the client airport information system; the construction instruction set at least comprises a basic image requirement instruction, a dependency registration instruction, and a tool chain parameter.

[0048] In this step, an adaptive construction strategy is automatically generated based on the actual software and hardware parameter data of the airport IT environment, supporting 10+ mainstream operating systems, 5 kernel versions, and 3 types of network strategies (public network / special network / hybrid network).

[0049] Figure 2 A specific example of the heterogeneous image construction method based on a multi-client environment in an embodiment of the present application is shown in Figure Figure 2 As shown, generating a construction instruction set according to the software and hardware environment parameter information of the client airport information system can comprise the following steps:

[0050] Step 201: obtaining the software and hardware environment parameter information of the client airport information system, structuring the software and hardware environment parameter information of the client airport information system, and obtaining structured environment parameters.

[0051] Step 202, determining specified environment information using structured environment parameters through regular expression matching;

[0052] Step 203, generating a construction instruction set using specified environment information through rule engine decision-making; the rule engine includes a base image determination method, a dependency repository configuration, a storage driver configuration, and a network proxy configuration.

[0053] For example, the software and hardware environment parameter information of a customer airport information system is structured into JSON format, and the structured environment parameters include: operating system version, kernel version, network {type: internal network, container image repository address}, software {high-performance open source server software identifier, version, code branch or custom code version}, and other typical data.

[0054] The target of regular expression matching in step 202 is to extract key fields from input parameters, for example, the rule definition is:

[0055] Operating system matching rule: ^ [a-zA-Z] + (\d +) $ → extract name and major version number (such as "cenxxx7" → name = cenxxx, version = 7);

[0056] Kernel version matching rule: ^ (\d + \. \d + \. \d +) → extract major version (such as "3.10.0" → major version = 3.10);

[0057] Network type matching rule: ^(public | internal | hybrid) $ → verify legality;

[0058] Regular expression matching results:

[0059] Operating system: cenxxx (major version 7);

[0060] Kernel version: 3.10;

[0061] Network type: internal.

[0062] Rule engine decision-making in step 203 includes a rule library (predefined logic tree):

[0063] If os = cenxxx and version = 7, then,

[0064] Given a list of base image candidates;

[0065] Given the dependency repository address, open source software package manager, and kernel compatibility check: need to support overlayfs storage driver (if kernel version < 3.18, then downgrade to vfs driver).

[0066] In this example, the rule base is stored in a tree structure, with the root node being the operating system and the child nodes being the kernel version, network type, etc. In the dependency rule base, the matching package version is searched, and if there are multiple matches, the optimal solution is selected according to the priority (airport security level > mirror volume > build time), and a dependency list D = {d1, d2,..., dm} is generated, containing package name, version number, repository address, etc. The minimum dependency set of the target environment is adapted to ensure full compatibility with kernel functions and network restrictions.

[0067] Finally, for example, the build instruction set is generated as follows:

[0068] {base image list; dependency registry; build tool chain: {package manager, storage driver, agent configuration} build command}.

[0069] In step 102, the base image is obtained based on the base image requirement instruction.

[0070] In implementation, the base image is obtained from a specified location according to the base image requirement.

[0071] In an embodiment, intelligent image selection is provided, and the base image requirement instruction includes architecture parameters of the customer airport information system;

[0072] Obtaining the base image based on the base image requirement instruction can include:

[0073] According to the architecture parameters, the base images with matching values exceeding a set threshold are checked from the image repository;

[0074] If the image repository does not have a base image with a matching value exceeding the set threshold, the OCI container image building tool is called to declare the configuration of the site to generate a minimized base image.

[0075] For example, based on the operating system and CPU architecture parameters obtained in step 101, the best matching items are searched from the image repository (containing 200+ base image metadata), such as Axxx:3.14 (ARM architecture) and Uxxx:20.04 (x86 architecture).

[0076] If there are no matching items in the image repository, the OCI container image building tool (APKO tool) is called to generate a minimized base image according to the YAMLl declarative configuration, and the default corresponding package manager is selected according to different operating systems to achieve automatic adaptation.

[0077] In an embodiment, format compatibility processing is performed. The base image requirement instruction further includes a base image format requirement;

[0078] Obtaining the base image based on the base image requirement instruction can include:

[0079] According to the basic image format requirements, the basic image format is converted into a format meeting the basic image format requirements by using a container image format conversion instruction.

[0080] In implementation, if a certain image format is needed, lossless conversion of different image formats can be realized by using underlying OCI technology to ensure cross-platform deployment. The image formats may be, for example, an OCI image format, a Docker image format, and the like.

[0081] In step 103, based on the underlying OCI standard, a container image is constructed by using a basic image, a dependency registration instruction, and a tool chain parameter.

[0082] In implementation, a daemonless construction is adopted, and container construction is realized based on the underlying OCI technology to adapt to a Docker runtime environment-free environment, such as a simplified system of an old airport.

[0083] In a multi-client heterogeneous IT environment, environment differences mainly exist in multiple dimensions such as operating systems, kernel versions, network strategies, hardware architectures, and software branches. In order to ensure that the container image can dynamically adapt to the infrastructure of different airports, the environment difference injection technology is used to automatically identify differences and adjust the construction strategy to ensure the compatibility, security, and efficiency of the image.

[0084] For example, kernel module adaptation: for the overlayfs function missing in the Linux 3.x kernel, a compatible layer is automatically mounted or replaced with a vfs storage driver.

[0085] For example, the support for introducing customer-defined environment differences includes: injecting a proxy configuration according to the network parameters set by the customer, and the proxy configuration is used to pull dependencies through a proxy server or a private warehouse in an airport that limits public network access. In implementation, static IP white list verification is supported to ensure network connectivity during image construction, and dependencies are pulled through a proxy server or a private warehouse in an airport that limits public network access, thereby preventing unauthorized nodes from accessing internal resources and reducing the risk of network attacks.

[0086] In an embodiment, based on the underlying Open Container Initiative (OCI) standard, a container image is constructed by using a basic image, a dependency registration instruction, and a tool chain parameter, which can include:

[0087] In the construction process of any image layer, the construction context directory, the dependency list, and the environment parameter are hashed to generate a unique construction identifier, and it is queried whether there is an image layer with the same construction identifier in a global layered cache warehouse. If an image layer with the same construction identifier is queried, the image layer construction is skipped. In this way, repetitive work can be greatly reduced, and construction efficiency can be improved.

[0088] In practice, the SHA-256 hash of the build context directory, dependency list, and environment parameters is generated to create a unique build identifier (BuildID). The global hierarchical cache repository is queried to determine if there is a public layer with the same BuildID. If a match is found, the layer construction is skipped. For layers that do not hit the cache, the rsync algorithm (remote synchronization algorithm or incremental synchronization algorithm) is used to compare file changes, and only the differences are transmitted. Combined with the cache mechanism, incremental updates are achieved.

[0089] During the container image construction process, the core of "using the rsync algorithm to compare file changes" is to compare the differences between two file system snapshots, which involves the comparison of the following two key objects:

[0090] Comparison objects:

[0091] Local build context (current state), the file system state in the current build task that has not been cached (such as the latest modification of code and configuration files). For example, the latest code files in the src / directory;

[0092] Cached layer (historical state), the image layer generated in the previous build (stored in the cache or local / remote cache repository). For example, the contents of the layer.tar file generated in the last build.

[0093] Difference comparison implementation process:

[0094] 1) Generate file snapshot:

[0095] Current state: Scan the build context directory (such as. / src) and calculate the hash value (such as SHA-256) of the files.

[0096] Cache state: Load the file list and hash value of the corresponding layer from the cache of the last build.

[0097] 2) Rsync algorithm comparison:

[0098] Comparison granularity: file level (such as file addition, deletion, or modification) or block level (partial change of large files).

[0099] Difference output: Only mark the files or file blocks that have changed.

[0100] 3) Incremental transmission:

[0101] Only the difference files (such as. / src / main.go) are used to generate a new layer.

[0102] Unchanged files (such as. / src / utils.go) are directly reused in the cache layer.

[0103] In implementation, the cache key is generated based on the build context hash, Dockerfile instructions, dependency versions, etc. Cache reuse: if the difference comparison result shows no changes, the layer construction is completely skipped.

[0104] In the construction phase, the command for cleaning the package manager cache is executed, such as yum clean all / apt-get autoclean, etc. The package manager cache and unused dependency libraries are deleted.

[0105] In step 104, the container image is modified for security compliance, resulting in a modified container image. Security compliance modification includes vulnerability scanning and repair, sensitive information identification and desensitization processing, and blocking of instructions that do not meet the preset airport information system security requirements.

[0106] Vulnerability scanning engine: integrate image scanning tools such as open source vulnerability scanning tools, grep or custom scripts for CVE (Common Vulnerabilities and Exposures) detection, support multi-dimensional scanning, and the underlying technology is to decompress image layer files through tar, scan file content layer by layer, including scanning operating system packages, application dependencies, runtime environments, etc. Set vulnerability level threshold, for example, prohibit high-risk vulnerabilities, and interrupt construction when the threshold is reached, and repair vulnerabilities.

[0107] Sensitive information detection: match image layer files through regular expressions to identify hardcoded passwords (such as / etc / shadow abnormal entries), unencrypted certificates, and other risk items, and then perform desensitization processing.

[0108] The preset airport information system security requirements include prohibiting default password accounts.

[0109] Modifying the container image for security compliance, resulting in a modified container image, can include: scanning for default password account information through regular matching or setting character matching, and modifying the password.

[0110] In implementation, built-in civil aviation industry safety specification file requirements are supported, and custom policy file import is supported, and non-compliant operations are blocked in real time during construction.

[0111] For example, a test account "test:test123" is left in a customized image of an airport, which is detected and blocked:

[0112] (1) Regular matching: scan files and match the password field of the test account;

[0113] (2) Strategy triggering: if non-encrypted hashes (such as plaintext `test123`) are found, the construction fails and an alarm is raised;

[0114] (3) Repair solution:

[0115] - Delete the test account or disable the account with `chage -E 0 test`.

[0116] - The password is changed to be dynamically injected by specifying a secure tool for managing sensitive data.

[0117] In step 105, the image layer reduction tool is used to reduce the image layer of the corrected container image, and the layer-reduced container image is obtained.

[0118] Figure 3 A specific example of the heterogeneous image construction method based on a multi-client environment in the embodiment of the application is shown in FIG. Figure 3 As shown in FIG. 1, the image layer reduction tool is used to reduce the image layer of the corrected container image, and the layer-reduced container image is obtained, including:

[0119] Step 301, using an image compression tool to analyze image layer dependency, visualizing image layer dependency and each image layer file proportion, and automatically marking redundant content; the redundant content includes temporary files and development tools;

[0120] Step 302, receiving the deletion instruction of the client to the redundant content;

[0121] Step 303, according to the deletion instruction, the image layer of the corrected container image is reduced, and the layer-reduced container image is obtained.

[0122] When implemented, first perform dependency analysis, use an image compression tool to analyze image layer dependency, visualize each layer file proportion, and automatically mark redundant content such as temporary files and development tools; whether to delete or retain these redundant content is determined according to the file type.

[0123] In the embodiment of the application, a layer merging technology is provided, and each layer (Layer) of the container image is a read-only file system difference set (such as newly added, modified, and deleted files). When multi-stage construction, each RUN, COPY, etc. instruction will generate a new layer, resulting in layer number expansion (for example, 15 layers), but only the final file state is required during actual operation. In this example, the intermediate layers generated by multi-stage construction are merged into 1-2 runtime layers through image compression and merging, and the number of image layers is reduced by combining parameters, and in a typical scenario, the number of layers is reduced from 15 to 3. The core logic is based on the final state of the file system and the optimization and reorganization of the layer dependency relationship.

[0124] Parse layer structure: read the manifest.json and layer tar file of the image, and construct the layer dependency tree.

[0125] Compute final state: Stack all layer file changes to generate a single filesystem snapshot (i.e. final state).

[0126] Recombine new layers: Split the snapshot into target number of layers (e.g. 1 base layer + 1 application layer), discard intermediate redundant layers.

[0127] Output: New image with significantly reduced number of layers, but consistent functionality with original image.

[0128] A specific example of a merge operation is to combine a 15-layer Nginx image into 3 layers as follows:

[0129] Layer 1: FROM cenxxx:7;

[0130] Layer 2: RUN yum install x1;

[0131] Layer 3: RUN yum install x2; ...

[0133] Layer 15: CMD ["nginx", "-g", "daemon off;"];

[0134] Merge all intermediate layers into 1 application layer (total 2 layers: base layer + application layer);

[0135] Merged layer structure:

[0136] Layer 1: FROM cenxxx:7 (base OS layer, unchanged);

[0137] Layer 2: Merged Layers 2-15 (includes all installation and configuration changes).

[0138] Finally, distribute the reduced layer container image to multiple repositories.

[0139] In the embodiment, the oras (OCI Registry As Storage, protocol with Open Container Initiative) protocol is supported to push to public cloud repositories, private image repositories, and industry-specific image libraries, and automatically handle authentication credentials (such as Token / certificate).

[0140] The embodiment of the application realizes multi-architecture support of the customer system, can generate ARM64 / x86_64 multi-platform images, realizes architecture-independent deployment through an image manifest list, and is suitable for airport edge computing devices such as security terminal of ARM architecture.

[0141] Embodiments of the present application comply with the semantic version specification (such as v1.2.3-airport=pek), record the construction environment fingerprint (such as os=cenxxx7-kernel=3.10-hash=abc123), support version backtracking and quick rollback.

[0142] The overall flow is described below by taking an example.

[0143] (1) environment parameter input;

[0144] (2) dynamic adaptation process;

[0145] (2.1) base image selection: determine the base image through rule base matching, and verify its kernel compatibility;

[0146] (2.2) network configuration injection: generate construction parameters, and replace the image source with the airport internal YUM warehouse;

[0147] (3) construction and optimization:

[0148] Initialize the container;

[0149] Install customized files;

[0150] Clean up redundant files;

[0151] Security scanning and layer optimization;

[0152] Block images containing high-risk vulnerabilities;

[0153] Generate a dependency analysis report;

[0154] Merge 12 intermediate layers into 2 running layers;

[0155] (4) distribution and verification, wherein the image volume is verified: reduced from 1.2GB to 380MB, and the startup time is shortened by 40%.

[0156] In summary, the embodiments of the present application provide the following key processing methods:

[0157] Dynamic adaptation method: rule engine driven base image and dependency version selection based on multi-dimensional environment parameters, specifically including APKO declarative configuration generation and skopeo format conversion technology;

[0158] Security compliance mechanism: mandatory integration of vulnerability scanning and sensitive information detection in the construction process, and support for blocking logic of custom industry policy file import;

[0159] Layered optimization technology: image volume minimization through image layer dependency analysis and layer merging;

[0160] Incremental build algorithm: public layer reuse mechanism based on content hash comparison, including build identifier BuildID generation and difference layer transmission logic.

[0161] The complete flow from environmental parameter analysis to image distribution, especially the combination of the core steps of dynamic dependency analysis → heterogeneous environment construction → security compliance detection → layered optimization, and the implementation method of multi-architecture image generation (such as ARM / x86) and cross-repository distribution.

[0162] The embodiment of the present application provides a special adaptation scheme for civil aviation heterogeneous environments, such as automatic identification of local repositories in private network environments, compatible module injection for old kernels (such as vfs storage driver replacement overlayfs), and synchronization mechanism for multi-client distributed cache.

[0163] The embodiment of the present application significantly improves the efficiency and quality of image construction in multi-client heterogeneous environments through dynamic adaptation, minimal construction, security embedding and cache sharing technology: based on the rule engine, more than 15 kinds of heterogeneous environments (including OS, kernel, network policy, etc.) are automatically adapted, the cross-field construction time is shortened by 65%, the repeated construction rate is reduced from 75% to less than 10%, and the human maintenance cost is reduced by 58%; with the help of declarative dependency management and layered optimization, the image size is reduced by an average of 72% (for example, container image is compressed from 1.2GB to 350MB), and the storage and transmission cost is reduced by 60%; the construction process is built-in vulnerability scanning and forced policy blocking, the high-risk vulnerability detection rate is increased by 40%, the security compliance detection coverage is 100%, and the risk response time is shortened from hours to minutes; specific solutions to private network in airports, compatibility of old kernels and other industry-specific problems are provided, multi-architecture automatic generation and cross-repository distribution are supported, the technology can be migrated to multi-node heterogeneous scenarios such as logistics and transportation, and the standardization and automation transformation of containerization of distributed IT systems are promoted, which has advanced technology and industrial application value.

[0164] The embodiment of the present application also provides a heterogeneous image construction device based on a multi-client environment, as described in the following embodiment. Since the principle of the device to solve the problem is similar to the method of constructing a heterogeneous image based on a multi-client environment, the implementation of the device can be referred to the implementation of the method of constructing a heterogeneous image based on a multi-client environment, and the repeated parts will not be described again.

[0165] Figure 4 A schematic diagram of the heterogeneous image construction device based on a multi-client environment in the embodiment of the present application is shown in FIG. 4, which includes: Figure 4

[0166] An environmental configuration analysis module 401 is configured to generate a construction instruction set according to the software and hardware environment parameter information of the client airport information system; the construction instruction set includes basic image requirement instructions, dependency registration instructions, and tool chain parameters. ​

[0167] a base image dynamic adaptation module 402, configured to obtain a base image based on a base image requirement instruction;

[0168] a heterogeneous perception construction module 403, configured to construct a container image based on the base image, a dependency registration instruction and a tool chain parameter based on a bottom-layer OCI standard; a public layer is shared through a global layered cache warehouse during the construction, and a customer's self-defined environment difference is supported to be introduced;

[0169] a security compliance module 404, configured to perform security compliance correction on the container image to obtain a corrected container image; the security compliance correction includes vulnerability scanning and repair, sensitive information identification and desensitization processing, and blocking of an instruction that does not meet a preset airport information system security requirement;

[0170] a layered optimization module 405, configured to perform image layer reduction on the corrected container image by using an image compression tool to obtain a layer-reduced container image;

[0171] a cross-airport image distribution module 406, configured to distribute the layer-reduced container image in multiple warehouses.

[0172] In an embodiment, the environment configuration analysis module 401 is specifically configured to:

[0173] obtain software and hardware environment parameter information of a customer airport information system, structure the software and hardware environment parameter information of the customer airport information system to obtain structured environment parameters;

[0174] determine specified environment information by using the structured environment parameters through regular expression matching;

[0175] generate a construction instruction set by using the specified environment information through rule engine decision; the rule engine includes a base image determination method, a dependency warehouse configuration, a storage driver configuration and a network proxy configuration.

[0176] In an embodiment, the base image requirement instruction includes an architecture parameter of the customer airport information system.

[0177] The base image dynamic adaptation module 402 is specifically configured to:

[0178] According to the architecture parameter, check a base image with a matching value exceeding a set threshold from an image warehouse;

[0179] If the image warehouse does not have a base image with a matching value exceeding the set threshold, call an OCI container image construction tool to declare a minimum base image on site.

[0180] In an embodiment, the base image requirement instruction further includes a base image format requirement.

[0181] The base image dynamic adaptation module 402 is specifically configured to:

[0182] According to the base image format requirement, the base image format is converted into a format meeting the base image format requirement by using a container image format conversion instruction.

[0183] In an embodiment, the heterogeneous perception construction module 403 is specifically configured to:

[0184] In the process of constructing any image layer, the construction context directory, the dependency list, and the environment parameter are hashed to generate a unique construction identifier, and it is queried whether there is an image layer with the same construction identifier in the global layered cache warehouse. If an image layer with the same construction identifier is queried, the construction of the image layer is skipped.

[0185] In an embodiment, the support for introducing customer self-defined environment differences includes:

[0186] According to the network parameter injection agent configuration set by the customer, the agent configuration is used to pull the dependency through the proxy server or the private warehouse in the airport limiting public network access.

[0187] In an embodiment, the preset airport information system security requirement includes prohibiting the default password account;

[0188] The security integration module 404 is specifically configured to:

[0189] The default password account information is scanned and found by regular matching or setting character matching;

[0190] The password is modified.

[0191] In an embodiment, the layered optimization module 405 is specifically configured to:

[0192] The image compression tool is used to analyze the image layer dependency relationship, the image layer dependency relationship and the file proportion of each image layer are visualized and displayed, and the redundant content is automatically marked. The redundant content includes temporary files and development tools.

[0193] The deletion instruction of the customer on the redundant content is received;

[0194] According to the deletion instruction, the image layer of the corrected container image is reduced to obtain the container image after the layer reduction.

[0195] The device 400 includes the complete system architecture of the cross-airport cache sharing warehouse of the environment configuration analysis module 401, the base image dynamic adaptation module 402, the heterogeneous perception construction module 403, the security integration module 404, the layered optimization module 405, and the cross-airport image distribution module 406. The modules interact with each other, such as the output of the analysis module driving the adaptation module to select the base image.

[0196] Figure 5 Fig. 1 is a schematic diagram of a computer device according to an embodiment of the present application. Figure 5 As shown in Fig. 1, the embodiment of the present application further provides a computer device 500, which comprises a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and capable of running on the processor 501, wherein the processor 501 implements the above-mentioned method for building heterogeneous image based on multi-client environment when running the computer program 503.

[0197] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the above-mentioned method for building heterogeneous image based on multi-client environment.

[0198] The embodiment of the present application further provides a computer program product, which comprises a computer program, wherein the computer program is executed by a processor to implement the above-mentioned method for building heterogeneous image based on multi-client environment.

[0199] The embodiment of the present application provides a container image building method and device with environmental adaptability, image lightness, building efficiency and security compliance, which has the following characteristics:

[0200] Dynamic environmental adaptation: automatically generate adaptive building strategies based on the actual hardware and software parameter data of the airport IT environment, support 10+ mainstream operating systems, 5 kernel versions and 3 network strategies (public network / private network / hybrid network);

[0201] Image minimization: through declarative dependency management and redundant layer cleaning, the image size is reduced by 60%-80% compared with traditional methods;

[0202] Building efficiency improvement: using hierarchical caching and parallel building technology, the single airport building time is shortened to within 15 minutes, and the cross-airport incremental building time is reduced by 70%;

[0203] Security compliance enhancement: integrate vulnerability scanning and strategy engine to achieve 100% image security detection coverage and block the distribution and deployment of non-compliant images.

[0204] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0205] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 one or more flowcharts and / or blocks

[0206] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 one or more flowcharts and / or blocks

[0207] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 one or more flowcharts and / or blocks

[0208] The above-described specific embodiments, the purpose, technical solutions and advantages of the present application are further described in detail, it should be understood that the above-described is only the specific embodiments of the present application, and is not used to limit the protection scope of the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A method for building a heterogeneous image based on a multi-customer environment, characterized in that: include: Generate a build instruction set based on the software and hardware environment parameter information of the customer's airport information system; the build instruction set includes basic image requirement instructions, dependency registration instructions, and tool chain parameters; Obtain the base image based on the base image requirement instructions; Based on the underlying Open Container Initiative (OCI) standard, container images are built using base images, dependency registration instructions, and toolchain parameters. During the build process, common layers are shared through a global layered cache repository, supporting the introduction of customer-defined environment differences. Perform security compliance corrections on container images to obtain corrected container images; security compliance corrections include vulnerability scanning and repair, sensitive information identification and desensitization, and blocking instructions that do not meet the preset airport information system security requirements; Use an image compression tool to reduce the image layers of the corrected container image to obtain a layer-reduced container image. After reducing the layers, the container image is distributed across multiple warehouses.

2. The method according to claim 1, wherein Generate a build instruction set based on the software and hardware environment parameter information of the customer's airport information system, including: Acquire software and hardware environment parameter information of the customer's airport information system, and structure the software and hardware environment parameter information of the customer's airport information system to obtain structured environment parameters; Use regular expression matching to determine the specified environment information using structured environment parameters; Through the decision-making of the rule engine, the construction instruction set is generated using the specified environment information; the rule engine includes the basic image determination method, dependency warehouse configuration, storage driver configuration, and network proxy configuration.

3. The method according to claim 1, wherein The basic image requirement instruction includes the architectural parameters of the customer's airport information system; Obtain a base image based on the base image requirements instructions, including: According to the architecture parameters, checking the image repository for a base image whose matching value exceeds a set threshold; If the image repository does not contain a base image with a matching value exceeding the set threshold, the OCI container image building tool is called to declaratively configure and generate a minimized base image on-site.

4. The method according to claim 3, wherein The base image requirement instruction also includes base image format requirements; Obtain a base image based on the base image requirements instructions, including: According to the basic image format requirements, use the container image format conversion instruction to convert the basic image format into a format that meets the basic image format requirements.

5. The method according to claim 1, wherein Based on the underlying Open Container Initiative (OCI) standard, a container image is built using base images, dependency registration instructions, and toolchain parameters, including: During the construction of any image layer, the build context directory, dependency list, and environment parameters are hashed to generate a unique build identifier. The global layered cache repository is queried to see if there is an image layer with the same build identifier. If an image layer with the same build identifier is found, the build of that image layer is skipped.

6. The method according to claim 1, wherein Support for introducing customer-defined environment differences includes: Inject proxy configuration based on customer-defined network parameters. This proxy configuration is used to pull dependencies through a proxy server or private repository within an airport that restricts public network access.

7. The method according to claim 1, wherein The aforementioned preset airport information system security requirements include prohibiting accounts with default passwords; Perform security compliance corrections on the container image to obtain the corrected container image, including: Scan and discover default password account information through regular expression matching or set character matching; Change your password.

8. The method according to claim 1, wherein Use an image compression tool to reduce the image layers of the corrected container image to obtain a layer-reduced container image, including: Use image compression tools to parse image layer dependencies, visualize image layer dependencies and the file ratio of each image layer, and automatically mark redundant content; the redundant content includes temporary files and development tools; Receive customer instructions to delete redundant content; The modified container image is reduced in image layers according to the deletion instruction to obtain a container image with reduced layers.

9. A heterogeneous image building device based on a multi-customer environment, characterized in that: include: The environment configuration parsing module is used to generate a build instruction set based on the software and hardware environment parameter information of the customer's airport information system; the build instruction set includes basic image requirement instructions, dependency registration instructions, and tool chain parameters; A base image dynamic adaptation module is used to obtain a base image based on a base image requirement instruction; The heterogeneous awareness building module is used to build container images based on the underlying OCI standard using base images, dependency registration instructions, and toolchain parameters. During the build process, common layers are shared through a global layered cache repository, supporting the introduction of customer-defined environment differences. The security compliance module is used to perform security compliance corrections on container images to obtain the corrected container images. Security compliance corrections include vulnerability scanning and repair, sensitive information identification and desensitization, and blocking of instructions that do not meet the preset airport information system security requirements. A layered optimization module is used to reduce the image layers of the corrected container image using an image compression tool to obtain a layer-reduced container image. The cross-airport image distribution module is used to distribute container images in multiple warehouses after layer reduction.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

12. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.