System resource isolation and scheduling method and device, electronic equipment and storage medium
By identifying tenants and dynamically routing them to independent database instances, encapsulating file service components, limiting the scope of file operations, and establishing resource quota boundaries through hardware-level isolation technology, the problems of data silos and resource contention in traditional actuarial systems have been solved, thereby improving management efficiency and business autonomy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- THE PEOPLES INSURANCE CO (GRP) OF CHINA LTD
- Filing Date
- 2025-11-13
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional actuarial systems suffer from problems such as data silos, resource contention, and inefficient management due to the lack of a multi-tenant dynamic balancing mechanism.
By identifying tenants, dynamically routing them to independent database instances, encapsulating file service components, restricting the scope of file operations, and establishing tenant-specific resource quota boundaries through hardware-level isolation technology, physical isolation of tenant data and resource scheduling are achieved.
It solved the problems of data silos and resource contention, improved management efficiency and business autonomy, and achieved physical isolation of tenant data and efficient utilization of resources.
Smart Images

Figure CN121883172A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a method and apparatus for isolating and scheduling system resources, an electronic device, and a storage medium. Background Technology
[0002] As a core technology in the insurance industry, actuarial systems are widely used in key business processes such as product pricing, risk assessment, and financial reporting. With the expansion of insurance groups' business scale and the upgrading of their digital transformation needs, the traditional actuarial system architecture has gradually revealed a systemic contradiction between management efficiency and business autonomy. Specifically, directly adopting a single architecture without establishing a dynamic balancing mechanism for multi-tenant scenarios leads to systemic problems such as data silos, resource contention, and management inefficiency. Summary of the Invention
[0003] This disclosure provides a method, apparatus, electronic device, and storage medium for isolating and scheduling system resources.
[0004] According to a first aspect of this disclosure, a method for isolating and scheduling system resources is provided, comprising: Acquire user access requests and identify tenant identities; establish tenant context information through tenant interceptors. Dynamically route tenant data to the corresponding independent database instance based on the tenant context information to achieve physically isolated storage of tenant data. The encapsulated file service component dynamically constructs a tenant-specific storage path, restricting tenant file operations to the scope of an independent partition directory; Computing resources are allocated based on tenant identity and preset resource policies, and tenant-specific resource quota boundaries are established through hardware-level isolation technology.
[0005] Optionally, obtaining user access requests and identifying tenant identities, and establishing tenant context information through a tenant interceptor includes: Store the tenant identifier in the context of the current thread to ensure global propagation of tenant information in the request processing chain; The database instance is globally uniquely identified using tenant coding naming rules.
[0006] Optionally, the step of dynamically routing tenant data to the corresponding independent database instance based on the tenant context information to achieve physically isolated storage of tenant data includes: Database connection parameters are generated based on tenant encoding using a dynamic data source routing component; wherein, the connection parameters include the database server address; Based on a physical-level isolation strategy, storage space is deployed independently for each tenant's database instance.
[0007] Optionally, the encapsulated file service component dynamically constructs a tenant-specific storage path to restrict tenant file operations to an independent partition directory, including: The routing module dynamically constructs the tenant's exclusive root directory path through file operations; Perform regular expression matching validation on the path string in the file operation request.
[0008] Optionally, the allocation of computing resources based on tenant identity and preset resource policies, and the establishment of tenant-specific resource quota boundaries through hardware-level isolation technology, includes: Allocate an independent CPU core limit and memory quota for each tenant process; A task-level priority scheduling algorithm is adopted to dynamically adjust the resource allocation weight according to the tenant's business type, giving priority to ensuring the computing resource needs of monthly settlement tasks.
[0009] Optionally, the method further includes: Automatic registration of computing nodes is achieved through a distributed monitoring service. When a monitoring node starts up, it sends a registration request to the management service based on its IP address, and establishes a node record with the IP address as the unique identifier. Periodically collect metrics on the CPU, memory, disk input / output, and network bandwidth of each computing node to generate real-time resource profiles and store them in a tenant-specific database table.
[0010] According to a second aspect of this disclosure, a system resource isolation and scheduling apparatus is provided, comprising: The acquisition unit is used to acquire user access requests and identify tenant identities, and to establish tenant context information through the tenant interceptor. The association unit is used to dynamically route tenant data to the corresponding independent database instance based on the tenant context information, thereby achieving physical isolation storage of tenant data. The encapsulation unit is used to encapsulate the file service component to dynamically construct the tenant's exclusive storage path, restricting the tenant's file operations to the scope of an independent partition directory; The allocation unit is used to allocate computing resources based on tenant identity and preset resource policies, and to establish tenant-specific resource quota boundaries through hardware-level isolation technology.
[0011] Optionally, the acquisition unit is further configured to: Store the tenant identifier in the context of the current thread to ensure global propagation of tenant information in the request processing chain; The database instance is globally uniquely identified using tenant coding naming rules.
[0012] Optionally, the association unit is further configured to: Database connection parameters are generated based on tenant encoding using a dynamic data source routing component; wherein, the connection parameters include the database server address; Based on a physical-level isolation strategy, storage space is deployed independently for each tenant's database instance.
[0013] Optionally, the packaging unit is further used for: The routing module dynamically constructs the tenant's exclusive root directory path through file operations; Perform regular expression matching validation on the path string in the file operation request.
[0014] Optionally, the allocation unit is further configured to: Allocate an independent CPU core limit and memory quota for each tenant process; A task-level priority scheduling algorithm is adopted to dynamically adjust the resource allocation weight according to the tenant's business type, giving priority to ensuring the computing resource needs of monthly settlement tasks.
[0015] Optionally, the device further includes: The sending unit is used to realize the automatic registration of computing nodes through the distributed monitoring service. When the monitoring node starts, it sends a registration request to the management service based on the IP address and establishes a node record with the IP address as the unique identifier. The data acquisition unit is used to periodically collect metrics such as the CPU, memory, disk input / output, and network bandwidth of each computing node, generate real-time resource profiles, and store them in a tenant-specific database table.
[0016] According to a third aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect above.
[0017] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the first aspect above.
[0018] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0019] The system resource isolation and scheduling method, apparatus, electronic device, and storage medium disclosed herein, through which the tenant identity can be identified and tenant context information established, thereby dynamically routing to the corresponding independent database instance to achieve physical data isolation and avoid data silos; by encapsulating a file service component to restrict tenant file operations to independent partition directories, data isolation is strengthened; at the same time, computing resources are allocated based on tenant identity and preset policies, and dedicated resource quota boundaries are established with the help of hardware-level isolation technology to prevent resource contention, thereby balancing management efficiency and business autonomy. Therefore, it can solve the technical problems of traditional actuarial systems, which adopt a single architecture and do not establish a multi-tenant dynamic balancing mechanism, resulting in difficulty in balancing management efficiency and business autonomy, as well as data silos, resource contention, and inefficient management. It achieves the technical effects of realizing physical isolation of tenant data, eliminating data silos, reducing resource contention, balancing management efficiency and business autonomy, and improving the management efficiency and business adaptability of insurance actuarial systems.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0021] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a flowchart illustrating a system resource isolation and scheduling method provided in an embodiment of this disclosure; Figure 2 A schematic diagram of the structure of a system resource isolation and scheduling device provided in an embodiment of this disclosure; Figure 3 A schematic diagram of the structure of a system resource isolation and scheduling device provided in an embodiment of this disclosure; Figure 4 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation
[0022] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0023] The following description, with reference to the accompanying drawings, describes a method, apparatus, electronic device, and storage medium for isolating and scheduling system resources according to embodiments of the present disclosure.
[0024] Figure 1 This is a flowchart illustrating a system resource isolation and scheduling method provided in an embodiment of this disclosure.
[0025] like Figure 1 As shown, the method includes the following steps: Step 101: Obtain user access requests and identify tenant identities; establish tenant context information through the tenant interceptor. After a user initiates a system access request, the request is first received and parsed to extract relevant information identifying the tenant. Then, a tenant interceptor with tenant identity verification and interception capabilities verifies the validity and uniqueness of the extracted tenant identity information. Once the tenant identity is confirmed, the tenant interceptor further constructs a tenant context containing the tenant's core identification information and temporarily stores this context to ensure it can be invoked throughout the entire processing cycle of the current access request, providing an identity benchmark for matching subsequent access requests with tenant-specific resources. As one implementation method, the tenant code can be extracted from the request header or request parameters as the tenant identity identifier. The tenant interceptor completes identity verification according to preset tenant identity verification rules, and the tenant context information is stored in ThreadLocal to ensure its independence and accessibility throughout the lifecycle of a single request.
[0026] By establishing a standardized tenant identification and context creation process, the accuracy and uniqueness of tenant identification are ensured, avoiding the risk of unauthorized tenant access. It also provides a unified tenant identification benchmark for subsequent data isolation, resource scheduling and other operations, effectively improving the standardization and accuracy of the system's handling of multi-tenant access requests.
[0027] Step 102: Dynamically route tenant data to the corresponding independent database instance based on the tenant context information to achieve physical isolation storage of tenant data; After obtaining and confirming the tenant context information, a preset dynamic data source routing mechanism is activated. This mechanism uses the unique tenant identifier contained in the tenant context as the core matching basis. By querying the preset tenant-database instance mapping relationship, it automatically locates and switches to the independent database instance that corresponds one-to-one with the current tenant. This ensures that all data read and write operations of the current tenant are directed to this dedicated independent database instance for storage processing, thus cutting off the interaction channel between different tenant data at the physical storage level and achieving physical isolation storage of tenant data. As one implementation method, the dynamic data source routing mechanism can rely on the tenant code stored in the tenant context to match a preset database instance routing table. The independent database instances are named according to the tenant code to ensure uniqueness. At the same time, database connections are dynamically managed through a data source connection pool to ensure efficient routing switching.
[0028] By combining tenant context-based dynamic routing with independent database instances, the system not only completely eliminates the risks of cross-tenant data storage and unauthorized access at the physical level, ensuring the security and independence of tenant data, but also achieves automatic and accurate matching between tenants and dedicated database instances without manual intervention in data storage orientation, effectively improving the automation level and reliability of the system's multi-tenant data storage and processing.
[0029] Step 103: Encapsulate the file service component to dynamically construct the tenant's exclusive storage path, restricting tenant file operations to the scope of an independent partition directory; The file service function is componentized and encapsulated to form a file service component with dynamic path generation and operation scope control capabilities. When receiving a tenant's file operation request, this component automatically calls the established tenant context information, extracts the tenant's unique identifier as the core basis for path concatenation, and dynamically combines it according to preset path generation rules to generate a storage path exclusive to the current tenant. At the same time, through a preset storage scope constraint mechanism, this exclusive storage path is directed to the tenant's corresponding independent partition directory, so that all read, write, and storage operations of the tenant's files are restricted to this independent partition directory, ensuring tenant file isolation from both the storage path and partition boundary dimensions. As one implementation method, the file service component can concatenate paths according to the rule of "basic storage root directory + tenant identifier + business subdirectory". The independent partition directory can be implemented using independent partitions of NAS distributed storage, and the component's built-in path traversal detection and access permission verification functions further strengthen boundary control.
[0030] By using component-based encapsulation and dynamic path concatenation, the system achieves both the customization and automated generation of tenant file storage paths, avoiding path errors caused by manual configuration; it also strictly defines the scope of file operations through partitioned directory restrictions, completely eliminating the risk of cross-tenant file access and mixed storage. At the same time, the component-based design also improves the maintainability and reusability of file service functions.
[0031] Step 104: Allocate computing resources based on tenant identity and preset resource policies, and establish tenant-specific resource quota boundaries through hardware-level isolation technology.
[0032] After identifying a tenant, a pre-defined resource policy tailored to the tenant's business attributes and needs is retrieved. Using the tenant's identity information as an identifier and the resource policy as the allocation basis, system computing resources are targeted and allocated. Simultaneously, hardware-level isolation technology is activated. Based on the resource quota standards specified in the resource policy, a dedicated resource usage boundary is constructed for the current tenant, ensuring that the tenant's computing tasks can only run within its allocated resource quota, thus preventing resource conflicts between different tenants at the hardware control level. As one implementation method, the pre-defined resource policy may include parameters such as the tenant's corresponding CPU usage limit and memory quota. The hardware-level isolation technology can be implemented using Linux cgroups and can dynamically adjust resource quotas according to the tenant's business cycle to meet the needs of resource protection during peak hours and resource reuse during off-peak hours.
[0033] By combining tenant identity with preset policies in the resource allocation logic, the system achieves precise matching of computing resources with tenant needs. Furthermore, by relying on the resource boundaries built with hardware-level isolation, it effectively avoids resource contention among tenants, ensures the stability of each tenant's metering tasks, and improves the overall utilization efficiency of the system's computing resources.
[0034] In some embodiments, obtaining user access requests and identifying tenant identities, and establishing tenant context information through a tenant interceptor includes: Store the tenant identifier in the context of the current thread to ensure global propagation of tenant information in the request processing chain; The database instance is globally uniquely identified using tenant coding naming rules.
[0035] After obtaining a user access request and identifying the tenant, when establishing tenant context information through the tenant interceptor, a thread-level context storage container is first created using ThreadLocal technology. This container is specifically used to store the unique identifier of the current tenant. During the request preprocessing stage, the tenant interceptor extracts the tenant identifier from the request header fields or request parameters of the access request. After validity verification, the tenant identifier is stored in the ThreadLocal container. Throughout the entire request processing chain, each processing module can directly obtain the current tenant identifier from the ThreadLocal container without passing additional parameters. Furthermore, after the request processing is completed, the tenant interceptor... The system will trigger the cleanup operation of the ThreadLocal container to avoid the reuse of tenant information caused by thread reuse. At the same time, for the naming of database instances, a globally unique naming rule of "fixed prefix + tenant unique code" is adopted. The fixed prefix is set to "TENANT_", and the tenant unique code is a 6-digit numeric code assigned by the system to each tenant (such as the code of tenant A is "000001"). Then the corresponding database instance is named "TENANT_000001_DB". When adding a new tenant, the system will automatically verify the uniqueness of the code to be assigned and the existing code to ensure that the generated database instance name is not repeated in the entire system cluster.
[0036] By storing tenant identifiers using ThreadLocal and enabling global propagation within the request chain, the ease and accuracy of obtaining tenant information at each processing stage are ensured, while avoiding information interference from different tenant requests in a multi-threaded environment. At the same time, cleanup operations can prevent memory leaks. Furthermore, the unified tenant coding and naming rules not only make the correspondence between database instances and tenants intuitive and clear, facilitating quick identification and management by operations and maintenance personnel, but also eliminate database instance name conflicts from the naming source through code uniqueness verification, ensuring the stability of the system storage architecture.
[0037] In some embodiments, the step of dynamically routing tenant data to the corresponding independent database instance based on the tenant context information to achieve physically isolated storage of tenant data includes: Database connection parameters are generated based on tenant encoding using a dynamic data source routing component; wherein, the connection parameters include the database server address; Based on a physical-level isolation strategy, storage space is deployed independently for each tenant's database instance.
[0038] The operation is initiated by the system's built-in dynamic data source routing component. This component first extracts the tenant code from the tenant context information, and then accesses the system's preset "tenant code-database connection parameter mapping table". This table stores a one-to-one correspondence between each tenant code and its corresponding database connection parameters. The component accurately matches the records in the table based on the extracted tenant code and automatically generates complete database connection parameters. These parameters include the core database server address, as well as the database service port, database instance name, and encrypted database access account and password. After generating the connection parameters, the component passes them to the data source connection pool. The connection pool establishes and maintains a stable connection with the target independent database instance based on these parameters, ensuring that subsequent data operations can be executed in a targeted manner. Meanwhile, when deploying tenant database instance storage space based on physical isolation strategies, the system allocates independent physical storage resources to each tenant's database instance: if a distributed storage architecture is adopted, a dedicated physical storage node will be assigned to each tenant's database instance, and the nodes will be isolated from each other through a physical network; if a centralized storage architecture is adopted, an independent physical disk partition will be divided for each tenant's database instance in the storage server. Each partition only stores the corresponding tenant's database data files, log files, and index files, and the partition access permissions will be set through the storage management system to allow only the corresponding tenant's database service process to access the partition.
[0039] The dynamic data source routing component automatically generates connection parameters containing server addresses based on tenant codes, eliminating the need for manual configuration of data source connections. This improves the efficiency and accuracy of data source routing and avoids connection errors caused by human error. Meanwhile, the physically isolated storage space deployment completely cuts off the interaction path between different tenant database files at the hardware storage level, minimizing the risk of cross-tenant data leakage or file corruption, while ensuring that the storage performance of each tenant's database is not affected by the resources occupied by other tenants.
[0040] In some embodiments, the encapsulation file service component dynamically constructs a tenant-specific storage path to restrict tenant file operations to the scope of an independent partition directory, including: The routing module dynamically constructs the tenant's exclusive root directory path through file operations; Perform regular expression matching validation on the path string in the file operation request.
[0041] When encapsulating the file service component to dynamically construct tenant-specific storage paths and restrict the scope of file operations, the file operation routing module built into the file service component first performs the path construction operation: the module first extracts the tenant's unique code from the established tenant context information, and then calls the system's preset tenant storage path generation rules, which are set as "basic storage root directory + tenant code + business type subdirectory".
[0042] By dynamically constructing tenant-specific root directories according to fixed rules through the file operation routing module, the uniqueness and standardization of each tenant's storage path are ensured, and the root directory is automatically bound to the independent NAS partition, avoiding path and partition mismatches caused by manual configuration. The regular expression matching and validation of the path string can accurately intercept operation requests containing path traversal or illegal format, eliminating the risk of tenants accessing other tenants' storage directories without authorization from the source, and further enhancing the security of tenant file storage.
[0043] In some embodiments, allocating computing resources based on tenant identity and preset resource policies, and establishing tenant-specific resource quota boundaries through hardware-level isolation technology includes: Allocate an independent CPU core limit and memory quota for each tenant process; A task-level priority scheduling algorithm is adopted to dynamically adjust the resource allocation weight according to the tenant's business type, giving priority to ensuring the computing resource needs of monthly settlement tasks.
[0044] When allocating computing resources based on tenant identity and preset resource policies, and establishing tenant-specific resource quota boundaries through hardware-level isolation technology, the first step is to configure an independent CPU core limit and memory quota for each tenant's computing process according to the system's preset resource policies for each tenant: through Linux. cgroups hardware isolation technology creates a dedicated cgroup control group for each tenant. Parameters are set in the CPU subsystem (e.g., for tenant C with a large business scale, a 4-core CPU limit is configured, with a corresponding parameter value of 400,000, or 4 × 100,000), strictly limiting the total CPU utilization of all processes within that tenant to no more than the allocated number of cores. A task-level priority scheduling algorithm is used: computational tasks are first divided into monthly settlement tasks and daily tasks based on the tenant's business type. Monthly settlement tasks are assigned a higher priority weight, while daily tasks are assigned a basic weight (e.g., 0.4). When allocating resources, the scheduler prioritizes reading the task type identifier. If a monthly settlement task is detected, it prioritizes allocating the preset number of CPU cores and memory resources to it. During peak monthly settlement periods, resources allocated to monthly settlement tasks are locked to prevent them from being preempted by daily tasks. During off-peak periods, daily tasks are allowed to reuse idle resources from monthly settlement tasks, and when a monthly settlement task is triggered, the scheduler can forcibly reclaim reused resources and allocate them to the monthly settlement task.
[0045] By configuring independent CPU core limits and memory quotas for tenant processes, combined with cgroups hardware-level isolation, disorderly contention for computing resources among tenants is eliminated from the bottom layer, ensuring the stability of each tenant's task execution. The task-level priority scheduling algorithm dynamically adjusts resource weights for month-end critical business, ensuring efficient execution of month-end tasks during peak business periods and avoiding task delays due to insufficient resources, while also enabling the reuse of idle resources during off-peak periods, thus improving the overall utilization efficiency of the system's computing resources.
[0046] In some embodiments, the method further includes: Automatic registration of computing nodes is achieved through a distributed monitoring service. When a monitoring node starts up, it sends a registration request to the management service based on its IP address, and establishes a node record with the IP address as the unique identifier. Periodically collect metrics on the CPU, memory, disk input / output, and network bandwidth of each computing node to generate real-time resource profiles and store them in a tenant-specific database table.
[0047] When executing the method, the automatic registration of computing nodes is first achieved through the distributed monitoring service deployed by the system: When the monitoring node on each computing node starts, the monitoring node will first extract its own IP address through the built-in network information acquisition module, and automatically assemble a registration request message containing the IP address, node hardware model, tenant identifier, and initial running status, and then send the message to the system's management service; after receiving the registration request, the management service will first query the stored node record database to verify whether the IP address already exists. If there is no duplicate IP, a node record with the IP address as the unique index will be created in the node record database. The record content includes the IP address, tenant identifier, hardware information, registration time, and initial status, thus completing the association between the monitoring node and the management service. Meanwhile, the distributed monitoring service triggers metric collection tasks at preset intervals (e.g., every 60 seconds): through the resource collection agent on the monitoring node, it collects in real time the CPU utilization (including overall utilization and utilization of each core), memory usage (used memory capacity / total memory capacity), disk I / O rate (including disk read rate, write rate and I / O wait time), and network bandwidth metrics (including network receive rate, send rate and bandwidth utilization). After collection, the monitoring agent integrates the metric data into structured real-time resource profile data containing node IP, metric type, metric value, and collection timestamp. Then, based on the tenant information to which the node belongs, it writes the resource profile data to the "node_resource_snapshot" table in the corresponding tenant's dedicated database, ensuring a clear relationship between resource monitoring data and tenant affiliation.
[0048] Automatic registration of compute nodes with unique IP addresses eliminates the maintenance costs of manually entering node information and avoids issues such as duplicate or missing node identifiers due to human error, ensuring the accuracy of compute node management. Periodically collecting multi-dimensional resource metrics and storing them in tenant-specific database tables not only provides maintenance personnel with a real-time and comprehensive view of node resource status to support resource scheduling decisions, but also ensures the isolation of monitoring data from business data through tenant-specific table storage, avoiding cross-tenant resource data interference.
[0049] Corresponding to the aforementioned system resource isolation and scheduling method, this invention also proposes a system resource isolation and scheduling device. Since the device embodiments of this invention correspond to the aforementioned method embodiments, details not disclosed in the device embodiments can be referred to the aforementioned method embodiments, and will not be repeated here.
[0050] Figure 2 This is a schematic diagram of the structure of a system resource isolation and scheduling device provided in an embodiment of the present disclosure, as shown below. Figure 2 As shown, it includes: Acquisition unit 21 is used to acquire user access requests and identify tenant identities, and to establish tenant context information through a tenant interceptor; The association unit 22 is used to dynamically route tenant data to the corresponding independent database instance based on the tenant context information, thereby achieving physical isolation storage of tenant data. Encapsulation unit 23 is used to encapsulate the file service component to dynamically construct the tenant's exclusive storage path, thereby restricting the tenant's file operations to the scope of an independent partition directory; Allocation unit 24 is used to allocate computing resources based on tenant identity and preset resource policies, and to establish tenant-specific resource quota boundaries through hardware-level isolation technology.
[0051] Furthermore, in one possible implementation of this disclosure, the acquisition unit 21 is further configured to: Store the tenant identifier in the context of the current thread to ensure global propagation of tenant information in the request processing chain; The database instance is globally uniquely identified using tenant coding naming rules.
[0052] Furthermore, in one possible implementation of this disclosure, the associated unit 22 is further configured to: Database connection parameters are generated based on tenant encoding using a dynamic data source routing component; wherein, the connection parameters include the database server address; Based on a physical-level isolation strategy, storage space is deployed independently for each tenant's database instance.
[0053] Furthermore, in one possible implementation of this disclosure, the encapsulation unit 23 is further configured to: The routing module dynamically constructs the tenant's exclusive root directory path through file operations; Perform regular expression matching validation on the path string in the file operation request.
[0054] Furthermore, in one possible implementation of this disclosure, the allocation unit 24 is further configured to: Allocate an independent CPU core limit and memory quota for each tenant process; A task-level priority scheduling algorithm is adopted to dynamically adjust the resource allocation weight according to the tenant's business type, giving priority to ensuring the computing resource needs of monthly settlement tasks.
[0055] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 3 As shown, the device further includes: Sending unit 25 is used to realize automatic registration of computing nodes through distributed monitoring service. When the monitoring node starts, it sends a registration request to the management service based on the IP address and establishes a node record with the IP address as the unique identifier. The acquisition unit 26 is used to periodically collect the central processing unit, memory, disk input / output and network bandwidth indicators of each computing node, generate real-time resource profiles and store them in the tenant-specific database table.
[0056] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.
[0057] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0058] Figure 4 A schematic block diagram of an example electronic device 400 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0059] like Figure 4 As shown, device 400 includes a computing unit 401, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 402 or a computer program loaded from storage unit 408 into RAM (Random Access Memory) 403. RAM 403 may also store various programs and data required for the operation of device 400. The computing unit 401, ROM 402, and RAM 403 are interconnected via bus 404. I / O (Input / Output) interface 405 is also connected to bus 404.
[0060] Multiple components in device 400 are connected to I / O interface 405, including: input unit 406, such as keyboard, mouse, etc.; output unit 407, such as various types of monitors, speakers, etc.; storage unit 408, such as disk, optical disk, etc.; and communication unit 409, such as network card, modem, wireless transceiver, etc. Communication unit 409 allows device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0061] The computing unit 401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 401 performs the various methods and processes described above, such as methods for isolating and scheduling system resources. For example, in some embodiments, the methods for isolating and scheduling system resources may be implemented as computer software programs tangibly contained in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed on device 400 via ROM 402 and / or communication unit 409. When the computer program is loaded into RAM 403 and executed by the computing unit 401, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, computing unit 401 may be configured to perform the aforementioned method of isolating and scheduling system resources by any other suitable means (e.g., by means of firmware).
[0062] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0063] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0064] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0065] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0066] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0067] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0068] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0069] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0070] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for isolation and scheduling of system resources, characterized in that, include: Acquire user access requests and identify tenant identities; establish tenant context information through tenant interceptors. Dynamically route tenant data to the corresponding independent database instance based on the tenant context information to achieve physically isolated storage of tenant data. The encapsulated file service component dynamically constructs a tenant-specific storage path, restricting tenant file operations to the scope of an independent partition directory; Computing resources are allocated based on tenant identity and preset resource policies, and tenant-specific resource quota boundaries are established through hardware-level isolation technology.
2. The method of claim 1, wherein, The steps of obtaining user access requests and identifying tenant identities, and establishing tenant context information through a tenant interceptor include: Store the tenant identifier in the context of the current thread to ensure global propagation of tenant information in the request processing chain; The database instance is globally uniquely identified using tenant coding naming rules.
3. The method of claim 1, wherein, The step of dynamically routing tenant data to the corresponding independent database instance based on the tenant context information to achieve physically isolated storage of tenant data includes: Database connection parameters are generated based on tenant encoding using a dynamic data source routing component; wherein, the connection parameters include the database server address; Based on a physical-level isolation strategy, storage space is deployed independently for each tenant's database instance.
4. The method according to claim 1, characterized in that, The encapsulated file service component dynamically constructs a tenant-specific storage path, restricting tenant file operations to the scope of an independent partition directory, including: The routing module dynamically constructs the tenant's exclusive root directory path through file operations; Perform regular expression matching validation on the path string in the file operation request.
5. The method according to claim 1, characterized in that, The allocation of computing resources based on tenant identity and preset resource policies, and the establishment of tenant-specific resource quota boundaries through hardware-level isolation technology, include: Allocate an independent CPU core limit and memory quota for each tenant process; A task-level priority scheduling algorithm is adopted to dynamically adjust the resource allocation weight according to the tenant's business type, giving priority to ensuring the computing resource needs of monthly settlement tasks.
6. The method according to claim 1, characterized in that, The method further includes: Automatic registration of computing nodes is achieved through a distributed monitoring service. When a monitoring node starts up, it sends a registration request to the management service based on its IP address, and establishes a node record with the IP address as the unique identifier. Periodically collect metrics on the CPU, memory, disk input / output, and network bandwidth of each computing node to generate real-time resource profiles and store them in a tenant-specific database table.
7. A system resource isolation and scheduling device, characterized in that, include: The acquisition unit is used to acquire user access requests and identify tenant identities, and to establish tenant context information through the tenant interceptor. The association unit is used to dynamically route tenant data to the corresponding independent database instance based on the tenant context information, thereby achieving physical isolation storage of tenant data. The encapsulation unit is used to encapsulate the file service component to dynamically construct the tenant's exclusive storage path, restricting the tenant's file operations to the scope of an independent partition directory; The allocation unit is used to allocate computing resources based on tenant identity and preset resource policies, and to establish tenant-specific resource quota boundaries through hardware-level isolation technology.
8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.
9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-6.