Service orchestration within a distributed pod-based system
By using custom resource allocation and isolation methods in a distributed computing environment, combined with containerization technology, the challenges of resource management and security in multi-cloud environments are solved, ensuring the privacy and security of medical data and supporting rapid and automated software deployment and service management.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2026-03-31
AI Technical Summary
Existing distributed computing environments present challenges in resource management and security, especially in multi-cloud environments. Traditional resource management strategies are ill-suited to containerized distributed computing environments and fail to meet the data privacy and security requirements of the healthcare industry.
It employs custom resource allocation and isolation methods, orchestrates services in a distributed computing environment through a cluster manager (kernel), utilizes containerization technology to configure resources according to service type, and builds containers using image templates and writable layers to achieve efficient service deployment and secure management.
It enables efficient and secure resource management in multi-cloud environments, reduces operating costs, ensures the privacy and security of medical data, and supports rapid and automated software deployment and service management.
Smart Images

Figure 0007837968000001 
Figure 0007837968000002 
Figure 0007837968000003
Abstract
Description
[Technical Field]
[0001] Priority Claim This application claims the benefit and priority of U.S. Provisional Patent Application No. 63 / 111,996, filed on November 10, 2020, which is incorporated herein by reference in its entirety for all purposes.
[0002] field This disclosure relates to digital personalized healthcare, and in particular to technologies for service orchestration within decentralized pod-based systems. [Background technology]
[0003] background A cluster manager (also known as the kernel of a distributed computing system) provides resource sharing between multiple different frameworks (e.g., stream processing, batch processing, data integration, storage frameworks, etc.). In some examples, a cluster manager includes: (i) agents that execute tasks from frameworks and notify about available resources; (ii) frameworks that provide services or solve specific use cases; and (iii) a master that mediates between agents and frameworks. A framework includes a scheduler that decides whether to accept or reject resources, and an execution unit that allocates accepted resources to tasks and controls the execution of tasks. Resource sharing provided by a cluster manager generally includes resource allocation and resource isolation. Resource allocation includes agents that report available resources, a master that determines the number of resources each framework provides, and frameworks that decide which resources to accept and which computations to perform on those resources. Resource isolation includes agents, masters, and frameworks that ensure that resources allocated to any given task are not consumed by another task.
[0004] In healthcare, data-driven technological solutions are being developed to further enhance personalized healthcare while reducing costs. As the healthcare landscape shifts to on-demand deployment systems for personalized medical services and solutions, healthcare providers are seeking help from developers to innovate solutions more quickly by automating and streamlining software deployment and service management processes. To support healthcare providers and services, developers have turned to distributed computing environments (e.g., cloud computing) as a healthcare information technology infrastructure standard—a low-cost way to develop the complex infrastructure necessary to support software deployment and service management processes within service models (e.g., Analytics as a Service (AaaS)). While distributed computing environments such as cloud computing offer many benefits to healthcare providers, they function differently from legacy storage or information sharing solutions and therefore present their own unique privacy and security challenges. For example, because users access data via internet connections, compliance with government regulations (e.g., the Healthcare Portability and Accountability Act (HIPAA), Good Practice Quality Guidelines and Regulations (GxP), and the General Data Protection Regulation (GDPR)) becomes a unique challenge for healthcare providers considering cloud solutions to support their software deployment and service management processes. Therefore, advancements are needed in compliant software deployment platforms built to ensure the confidentiality, availability, and integrity of protected healthcare information. [Overview of the Initiative]
[0005] overview In various embodiments, a computer implementation method comprising: receiving a first request in a first kernel residing in a first distributed computing environment to initiate a deployment process for a first sub-service or service on the first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; Essential request Receiving , and A first sub-service or service which is configured to be supported by the first distributed computing environment. Thailand Pu In response, a computer implementation method is provided, comprising provisioning specified resources in a deployment ring of a first distributed computing environment by a first kernel, provisioning being a template for a software package containing specifications for resources used to run a software package, and the template being customized to use the specified resources based on the first sub-service or service type
[0006] In some embodiments, resource placement includes parsing an image to identify specified resources, requesting available resources from a placement ring, parsing the available resources from the placement ring, determining, based on the parsing of the available resources, whether all of the specified resources from the image are available in the placement ring, and, in response to the fact that not all of the specified resources from the image are available in the placement ring, automatically scaling the available resources based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image.
[0007] In some embodiments, acquiring an image further includes identifying an image from a plurality of images based on a first sub-service or service type, wherein the image is configured in accordance with security best practices to mitigate image vulnerabilities, and security best practices are selected based on the first sub-service or service type.
[0008] In some embodiments, the image is further configured according to an image specification to optimize the deployment workflow and performance, and the image specification is selected based on the type of a first sub-service or service.
[0009] In some embodiments, the first sub-service or type of service is machine learning model software, software as a medical device, software that works in conjunction with a physical medical device, or data acquisition and processing software.
[0010] In some embodiments, the method further includes the kernel executing a first sub-service or service, which includes the kernel master determining a framework for executing the first sub-service or service based on the type of the first sub-service or service; the kernel master offering the framework available resources in the deployment ring to execute one or more programs to provide the first sub-service or service; the kernel master receiving information about a task defined by one or more programs in response to the offer; and the kernel master sending the task to a kernel agent that allocates the specified resources to the execution unit of the framework for executing the task.
[0011] In some embodiments, the method further includes the kernel exposing a first sub-service or service, and the kernel initiating security for the first sub-service or service.
[0012] In some embodiments, the method further includes the kernel performing a health check to evaluate the functionality of a first sub-service or service and to determine whether the first sub-service or service is functioning as expected, and notifying the Continuous Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected if the health check fails, and notifying the CICD system that a first request has been received from the CICD system, and when the first sub-service or service is functioning as expected, (i) the kernel exposes the first sub-service or service, (ii) the kernel initiates security for the first sub-service or service, and (iii) notifying the CICD system that the first sub-service or service has successfully functioned as expected.
[0013] In some embodiments, the method involves receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of a service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; and in response to receiving the request, provisioning a specified resource in the deployment ring of the second distributed computing environment by the second kernel, wherein provisioning is based on the type of the second sub-service or service, and the image is the resource used to run the software package. Provisioning includes a software package template containing the specifications of a second sub-service or service, the template being customized to use specified resources based on the type of second sub-service or service, the template being customized to use specified resources based on the type of second sub-service or service, the template being prepared to retrieve, the specified resources being prepared within a deployment ring, and the provisioning including constructing one or more containers using an image that encapsulate the specified resources, the one or more containers being prepared to wrap in a second pod for running one or more programs to provide the second sub-service or service, and modifying the image using a writable layer to include the source code necessary to run one or more programs, and further including deploying the second sub-service or service using one or more replicas of the second pod and the modified image by a second kernel.
[0014] Some embodiments of this disclosure include a system comprising one or more data processors. In some embodiments, the system includes a non-temporary, machine-readable storage medium containing instructions that, when executed on one or more data processors, cause one or more data processors to execute some or all of the methods and / or some or all of the processes disclosed herein. Some embodiments of this disclosure include a computer program product tangibly embodied in a non-temporary, machine-readable storage medium containing instructions configured to cause one or more data processors to execute some or all of the methods and / or some or all of the processes disclosed herein.
[0015] The terms and expressions used are for illustrative purposes only, not limitation, and in using such terms and expressions, there is no intention to exclude any equivalent or part of any of the features shown and described, however it should be recognized that various modifications are possible within the scope of the invention described in the claims. Accordingly, although the invention described in the claims is specifically disclosed by embodiments and optional features, modifications and variations of the concepts disclosed herein may be relied upon by those skilled in the art, and it should be understood that such modifications and variations are considered to be within the scope of the invention as defined by the appended claims. [Brief explanation of the drawing]
[0016] This disclosure is described in conjunction with the following attached drawings:
[0017] [Figure 1] This diagram illustrates a digital health platform for providing data-driven technology solutions across various embodiments.
[0018] [Figure 2] The diagrams show kernels for various embodiments.
[0019] [Figure 3] A block diagram of a process for service orchestration within a distributed pod-based system according to various embodiments is shown.
[0020] [Figure 4] A swimlane diagram showing a process for deploying a sub-service or service to a digital health platform using a kernel according to various embodiments is shown.
[0021] [Figure 5] A flowchart showing a process for deploying one or more sub-services of a service on a software platform according to various embodiments is shown.
[0022] In the accompanying drawings, similar components and / or features can have the same reference labels. Further, various components of the same type can be distinguished by following a dash and a second label that distinguishes the similar components after the reference label. If only the first reference label is used herein, the description is applicable to any of the similar components having the same first reference label regardless of the second reference label.
DETAILED DESCRIPTION OF THE INVENTION
[0023] Detailed Description I. Overview This disclosure describes techniques for service orchestration within a distributed pod-based system. More specifically, embodiments of this disclosure provide techniques for provisioning and deploying at least a portion of services (hereinafter referred to as sub-services) within a distributed pod-based system by a cluster manager (hereinafter referred to as a kernel) based on the type of the sub-service or service.
[0024] The kernel provides resource allocation and isolation across applications or frameworks within a distributed computing environment (e.g., cloud computing). Cloud computing typically relies on virtualization, which involves provisioning cloud-based applications and services using virtual resources such as virtual machines. Efficient management of these resources is a challenge because it directly impacts both the scalability and operational costs of the distributed computing environment. One type of virtualization technology is containers, which offer resource portability and require minimal overhead compared to traditional virtual machines. However, traditional resource management strategies are designed for allocating and migrating virtual machines, raising the challenge of how to adapt these strategies to managing a containerized distributed computing environment. Separately, cloud computing solutions such as AaaS and Software as a Service (SaaS) are also no longer limited to a single distributed computing environment. In some cases, services are provisioned and deployed across multiple distributed computing environments (i.e., multi-cloud solutions using multiple cloud providers and their provided computer hardware and physical network infrastructure to meet various technical or business requirements), thereby enabling organizations to offer a greater set of features than could be obtained from a single distributed computing environment, build a portable software stack that is vendor-lock-free and DevOP-driven. However, traditional resource management strategies are designed for allocating and migrating virtual machines within a single distributed computing environment, creating an additional challenge of how to adapt these strategies to managing multiple containerized distributed computing environments.
[0025] To address these limitations and challenges, the technology for service orchestration within a distributed pod-based system in this disclosure utilizes customized methods for resource allocation and isolation. This technology is intended to provision resources for sub-services or services deployed in a distributed computing environment. The deployed sub-services or services have a type, and the type of sub-service or service deployed on a given distributed computing environment must be configured to be supported by the distributed computing environment. The type of sub-service or service may be model software such as machine learning models, regression models, or any other type of supervised or unsupervised model, machine learning model software, software as a medical device (SAMD), software that works in conjunction with a physical medical device, or data ingestion and processing software. Furthermore, the sub-services or services are deployed using one or more containers wrapped in a pod. The one or more containers are configured using images obtained based on the type of sub-service or service to be deployed within the one or more containers. Each image is a binary containing metadata describing all the requirements for running a single container, as well as the needs and capabilities of the container.
[0026] One exemplary embodiment of the present disclosure is a method comprising receiving a first request in a first kernel residing in a first distributed computing environment to initiate a deployment process for a first sub-service or service on the first distributed computing environment. The first sub-service or service has a type, and for the first sub-service or service to be deployed on the first distributed computing environment, the type of the first sub-service or service must be configured to be supported by the first distributed computing environment. The method is as follows: Essential request Receiving , and A first sub-service or service which is configured to be supported by the first distributed computing environment. Thailand PuIn response, the method further includes provisioning specified resources in a deployment ring of a first distributed computing environment by a first kernel. Provisioning includes obtaining an image based on a first sub-service or service type, where the image is a template for a software package containing specifications for resources used to run the software package, and the template is customized to use the specified resources based on a first sub-service or service type; deploying the specified resources in a deployment ring; constructing one or more containers using the image that encapsulate the specified resources, where one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service; and modifying the image using a writable layer to include the source code necessary to run one or more programs. The method further includes deploying the first sub-service or service using one or more replicas of the first pod and the modified image by a first kernel.
[0027] In some cases, the method further includes receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of a service on the second distributed computing environment. The second sub-service or service has a type, and for the second sub-service or service to be deployed on the second distributed computing environment, the type of the second sub-service or service must be configured to be supported by the second distributed computing environment. In response to receiving the request and the type of the second sub-service or service which is configured to be supported by the second distributed computing environment, the method further includes provisioning a specified resource in the deployment ring of the second distributed computing environment by the second kernel. Provisioning includes obtaining an image based on a second sub-service or service type, where the image is a template for a software package containing specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service type; placing the specified resources in a deployment ring; and using the image to construct one or more containers that encapsulate the specified resources, where one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service; and modifying the image using a writable layer to include the source code necessary to run one or more programs. The method further includes deploying the second sub-service or service using one or more replicas of the second pod and the modified image by a second kernel.
[0028] II. Digital Health Platform Figure 1 shows a simplified diagram of a digital health platform 100 for providing data-driven technology solutions according to various embodiments. In the illustrated embodiment, the digital health platform 100 includes client computing devices 105 connected to a cloud-based infrastructure 110 via a network 115 including a network gateway 120 and a network mesh 125. The infrastructure 110 is adapted to run services or software applications in service pods 130 using resources provisioned within a deployment ring 135 by a cloud service provider 140 (e.g., a distributed computing environment) using various hardware and cloud infrastructure (e.g., private or on-premises cloud infrastructure and public cloud infrastructure). These services or software applications may be delivered to users of the client computing devices 105 as web-based or cloud services, for example, under an AaaS or SaaS model. Several providers, such as Amazon, Google, and Oracle, offer cloud services. The term cloud service is generally used to refer to services made available to users on demand via a communication network such as the Internet by a service provider's system (e.g., infrastructure 110), such as a government regulatory entity. Therefore, consumers can use cloud services provided by service providers without having to purchase separate licenses, support, or hardware and software resources to support the services. For example, a cloud service provider's system may host one or more programs, and users can use one or more programs on demand via the internet without having to purchase infrastructure resources to run one or more programs themselves.Cloud services are designed to provide easy and scalable access to applications, resources, and services.
[0029] In some cases, a user operating the client computing device 105 (e.g., a software or service consumer) utilizes one or more client applications to consume software products, services, or systems provided by various components 145 of the infrastructure 110. In other examples, a user operating the client computing device 105 (e.g., a developer) utilizes one or more client applications to upload the source code of software products, services, or systems provided by various components 145 of the infrastructure 110. Component 145 includes one or more processors, hardware components, or software components that can be run by a combination thereof. It should be understood that various different system configurations are possible, and these may differ from those shown for the digital health platform 100. Therefore, the embodiment shown in Figure 1 is an example of a distributed computing environment for implementing the digital health platform, and is not intended to be limiting.
[0030] The client computing device 105 includes various types of computing systems such as portable handheld devices, general-purpose computers such as personal computers and laptops, workstation computers, wearable devices, game systems, thin clients, various messaging devices, sensors or other sensing devices. These computing devices support various mobile operating systems (e.g., Microsoft Windows Mobile). (登録商標), various types and versions of software applications and operating systems, including iOS (registered trademark), Windows Phone (registered trademark), Android (trademark), BlackBerry (registered trademark), Palm OS (registered trademark), etc. (e.g., Microsoft Windows (登録商標) , Apple Macintosh (登録商標) , UNIX (登録商標) or UNIX-based operating systems, Linux or Linux-based operating systems such as Google Chrome (trademark) OS). The portable handheld device can be a mobile phone, smartphone (e.g., iPhone (登録商標) ), tablet (e.g., iPad (登録商標) ), personal digital assistant (PDA), etc. Wearable devices can include Fitbit Versa (商標) smartwatches, magic leap1 (登録商標) , HTV Vive, and Oculus (登録商標) and other virtual reality (VR) or augmented reality (AR) systems, and other devices. Game systems can include various handheld game devices, Internet-connected game devices (e.g., Microsoft Xbox (登録商標) game console with or without a gesture input device, Sony PlayStation (registered trademark) system, various game systems provided by Nintendo (registered trademark), and others). The client device 105 may be enabled to execute various different applications such as various Internet-related applications, communication applications (e.g., email applications, short message service (SMS) applications), etc., and may use various communication protocols.
[0031] Network 115 is any type of network well known to those skilled in the art that can support data communication using any of the various available protocols, including but not limited to TCP / IP (Transmission Control Protocol / Internet Protocol), SNA (System Network Architecture), IPX (Internet Packet Switching), and AppleTalk®. Just as examples, Network 115 could be a local area network (LAN), Ethernet, Token Ring, wide area network (WAN), internet, virtual network, virtual private network (VPN), intranet, extranet, public switched telephone network (PSTN), infrared network, or wireless network (e.g., IEEE 1002.11 protocol suite, Bluetooth). (登録商標) This can be a network operating under any of the following and / or any other radio protocols, and / or any combination of these and / or other networks.
[0032] The network gateway 120 is a network node that forms a secure path between multiple networks 115 operating on the same or different protocols. The network gateway 120 may provide network security using one or more of the following techniques: a firewall to monitor incoming and outgoing network traffic, a virtual private network to provide a private and secure communication channel, security scanning to identify security vulnerabilities in the network, and an access manager for authentication and authorization services. The network gateway 120 routes network traffic using service connectors that manage access to routers and various software products, services, or systems (e.g., using a service subscription business model). The network mesh 125 is a local network topology in which infrastructure 110 (e.g., bridges, switches, and other infrastructure devices) connect directly, dynamically, and non-hierarchically to as many other nodes as possible, working together to efficiently route data between devices and nodes. The network mesh 125 manages connectivity using one or more of the following techniques: load balancing, product, service, or system discovery, network access, routing, and peering, traffic mirroring, etc. Network 115, network gateway 120, and network mesh 125 work together to manage all data flowing in or out of infrastructure 110.
[0033] Component 145 includes one or more general-purpose computers, dedicated server computers (including, for example, PC (personal computer) servers, purpose-specific servers, midrange servers, mainframe computers, rack-mount servers, etc.), server farms, server clusters, or any other suitable configuration and / or combination of computers or systems that operate individually or in combination to provide resources, data, services, or programs to client computing devices 105 via the network 115. Component 145 may further include other computing architectures that include virtualization, such as one or more virtual machines running a virtual operating system, or one or more flexible pools of logical storage devices that can be virtualized to maintain virtual storage devices. In various embodiments, component 145 is adapted to run one or more services or software applications that provide the functionality described in this disclosure.
[0034] Component 145 also includes one or more data repositories. These data repositories may be used in various embodiments to store data and other information. For example, one or more of the data repositories may be used to store information for providing data-driven technology solutions such as SAMD, and to store information for verifying and deploying source code for implementing data-driven technology solutions. The data repositories may reside in various locations. For example, a data repository used by a component may be local to the component, or it may be remote from the component and communicate with the component via a network-based or dedicated connection. The data repositories may be of different types. In certain embodiments, a data repository used by a component may be a database, such as a centralized database, a distributed database, a NoSQL database, or a relational database. One or more of these databases may be adapted to allow the storage, updating, and retrieval of data to and from the database in response to SQL-formatted commands. In certain embodiments, one or more of the data repositories may also be used by an application to store application data. A data repository used by an application may be of different types, such as a key-value store repository, an object store repository, or a general storage repository supported by a file system.
[0035] Component 145 also includes compute nodes adapted to run one or more programs, such as services or software applications that provide the functionality described in this disclosure (e.g., services or software applications delivered as web-based or cloud services, or applications for implementing continuous integration and continuous deployment (CI / CD) systems). Each node is optionally a representation of a single machine implemented within a cluster of nodes. A single machine may be a physical machine (e.g., a server in a data center) or an Amazon Web Services server with a set set of available CPU and RAM resources. (商標) These may be virtual machines hosted on a cloud provider such as AWS. In a cluster, nodes pool their resources to form a more powerful machine. Once one or more programs are deployed on the cluster, the cluster intelligently handles the distributed work to the individual nodes. As nodes are added or removed, the cluster can shift work as needed. Which individual machine is actually running the code is not important to one or more programs or to the infrastructure.
[0036] One or more programs deployed on one or more clusters are packaged as containers. Containers are a widely accepted standard, and various images can be defined to deploy one or more programs on infrastructure 110. Containerization allows infrastructure 110 to create self-contained execution environments. Any program and all its dependencies can be bundled into a single file and then shared on infrastructure 110. Container creation can be done programmatically, enabling a powerful, fully automated CI / CD pipeline used for verifying and deploying code on infrastructure 110. Containers are wrapped in a higher-level structure known as a pod 130. Containers within the same pod 130 can share the same resources and local network. In some cases, containers can communicate with other containers within the same pod 130 as if they were on the same machine, while maintaining some degree of isolation from others. Pods 130 are used as replication units within infrastructure 110. If a program or resources are strained by processing and a single pod 130 instance cannot bear the load, the infrastructure 110 may be configured to deploy new replicas of pod 130 to the cluster as needed. Even when there is no heavy load, it may be beneficial to have multiple copies of pod 130 running at all times in the production system to enable load balancing and fault tolerance. One or more instances of pod 130 are provisioned to a cloud infrastructure system provided by one or more cloud service providers 140.
[0037] A cloud infrastructure system provided by one or more cloud service providers 140 includes infrastructure resources used to facilitate the provision of one or more instances of pods 130 that support various cloud services provided by infrastructure 110. To facilitate the efficient use of these resources for provisioning one or more instances of pods 130, the resources may be bundled into a set of resources or resource modules (also called a “placement ring 135”). Each resource module or placement ring 135 may contain a pre-integrated and optimized combination of one or more types of resources. In certain examples, different placement rings 135 may be pre-provisioned for different types of cloud services. For example, a first set of placement rings 135 may be provisioned for SAMD services, and a second set of placement rings 135 may contain a different combination of resources than the placement rings 135 in the first set of placement rings 135, and may be provisioned for data analytics services, and so on. For some cloud services, the resources allocated to provision the services may be shared among the services.
[0038] The digital health platform 100 further includes one or more kernels 150. Each kernel 150 is adapted to operate on each cloud infrastructure system (e.g., a distributed computing environment) provided by one or more cloud service providers 140. The kernel 150 is a cluster manager that provides resource allocation and isolation across distributed applications or frameworks throughout the digital health platform 100. The kernel 150 provides one or more programs with an application programming interface (API) for orchestrating services and software, including resource management and scheduling. The architecture of the kernel 150 includes agent nodes for executing tasks, master nodes for submitting tasks to the agent nodes, area managers for election and for looking up the addresses of the master nodes, and a framework for coordinating with the master nodes to schedule tasks on the agent nodes.
[0039] The digital health platform 100 further includes a CI / CD system 155. The CI / CD system 155 is implemented within a cloud infrastructure system, enabling the digital health platform 100 to frequently update, test, and deliver changes within the source code of software products, services, or systems. As detailed herein, in healthcare, there are government regulations regarding data security (e.g., data integrity and data privacy) that software must comply with. The CI / CD system 155 allows these policy regulations to be incorporated into the code, enabling compliance to be automatically tracked, verified, and reconfigured. In the SAMD example, data storage locations, server access control, and activity logging may be incorporated into the source code, ensuring user data is protected and managed during software use. Encryption and password-protected behavior may be further incorporated during continuous integration. During continuous delivery, security and monitoring tools may be used to track user activity and detect errors that could lead to security threats.
[0040] The CI / CD system 155 may also be used to provision machine learning models. While machine learning models are initially trained using datasets, over time, the model may drift or the data may change, leading to the need for updated machine learning models. If the machine learning model runs within a software application, the code associated with the software application can include triggers for when the machine learning model should be retrained. For example, the code may include instructions to retrain the machine learning model at predetermined time intervals when new training data is available or when it is determined that the machine learning model's performance falls below a threshold. Furthermore, software developers may explore variations in the model architecture and hyperparameters in a test environment based on monitoring the performance of the machine learning model in a production environment or based on estimated improvements for model optimization. The CI / CD system 155 facilitates building, testing, and deployment to production environments once it is determined that the machine learning model meets performance requirements.
[0041] III. Kernel Figure 2 shows a simplified diagram of a kernel 200 (e.g., kernel 150 as described in relation to Figure 1) for resource allocation and isolation across distributed applications or frameworks, relating to various embodiments. In the illustrated embodiments, kernel 200 includes software logic for a framework that includes a master 205, a backup master 210, a region manager 215, agents 220(a-n), and a scheduler 225 and execution unit 230. Kernel 200 groups and provisions resources 235 within a container-based environment based on the type of sub-service or service deployed in the distributed computing environment. In particular, the type of sub-service or service must be configured to be supported by the distributed computing environment. The type of sub-service or service can be model software such as machine learning models, regression models, or any other type of supervised or unsupervised model, machine learning model software, SAMD, software that works in conjunction with physical medical devices, or data ingestion and processing software. This limitation by type helps in the efficient and effective management of resources 235 and has a positive direct impact on both the scalability and operational costs of the distributed computing environment. Using basic scripts or complex "orchestrators," developers can quickly recover crashed sub-services or service components, add new instances to meet increased demand, or perform rolling upgrades to update sub-services or services without any downtime. Furthermore, container-based environments are lighter than virtual machines and can share a single operating system, significantly reducing infrastructure costs.
[0042] The kernel 200 groups together the resources 235 of machines / nodes located within a cluster or deployment ring into one or more containers 240(a-n) wrapped in a single pod instance 245(a-n), from which various tasks 250 for one or more programs can be executed, utilizing the resources 235 to provide sub-services or services. The one or more containers 240(a-n) are configured using images obtained based on the type of sub-service or service to be deployed within the one or more containers. Each image is a binary containing metadata describing all the requirements for running a single container, as well as the needs and capabilities of the container. Containers enable developers to create a consistent and reproducible environment that is isolated from one another and can contain dependencies. While isolation is not perfect (for example, authorized services can communicate with each other via API calls), containers isolate critical resources such as container access to underlying CPU, memory, storage, and network resources between each container. This reduces the possibility of individual containers consuming excessive resources and also prevents potential security issues.
[0043] The Area Manager 215 is a centralized configuration manager used by the kernel 200 to coordinate activities across clusters or placement rings. The Area Manager 215 can provide fault tolerance by selecting a leading master 205, a backup master 210 to replace a failed leading master 205, and agents 220 to participate in the cluster or placement ring. The master 205 manages the agents 220 running on each cluster node and the frameworks that perform tasks on the agents 220. The master 205 implements the provisioning of specific resources within the cluster or placement ring and fine-grained sharing between frameworks using resource offerings. Each resource offering is a list of available resources 235 that multiple agents 220 can utilize. The master 205 determines the number of resources 235 to provide to each framework according to organizational policies such as fair sharing or priority. To support a diverse set of inter-framework allocation policies, the kernel 200 is adapted to allow users to define their own policies via pluggable allocation modules.
[0044] Each framework running on kernel 200 consists of two components: a scheduler 225 that registers the resources 235 to be provided with the master 205, and an execution unit 230 that is started on agent 220 to execute the framework's tasks 250. The master 205 determines the number of resources 235 to provide to each framework, while the framework's scheduler 225 selects which of the provided resources 235 to use. Once a framework accepts the provided resources 235, it passes a description to the master 205 of the tasks 250 defined by one or more programs that the framework wants to run on agent 220. For example, a framework may schedule one or more tasks to run as follows: First, agent 220 reports to the master that it has resources 235, such as 6 CPUs and 9GB of free memory. Then, master 205 calls an allocation module that informs master 205 that the framework should be provided with all available resources. Master 205 then sends a resource provision to the framework describing all available resources 235. The framework's scheduler 225 uses three CPUs; 1GB of RAM for the first task, and two CPUs; 6GB of RAM for the second task to respond to the master 205 with information about tasks 250 defined by one or more programs, for example, two tasks to run on an agent. Finally, the master 205 sends the tasks 250 to the agent 220, which allocates the appropriate resources 235 to the framework's execution unit 230 and starts the two tasks. Since one CPU and 2GB of RAM are still available, the allocation module can provide these to another framework. Furthermore, this resource provisioning process is repeated when tasks finish and new resources become available.
[0045] IV. Technologies for deploying services on a digital health platform Figures 3-5 illustrate the processes and operations for service orchestration within a distributed pod-based system. Individual embodiments may be described as processes represented as flowcharts, flow diagrams, data flow diagrams, structural diagrams, or block diagrams. While flowcharts may describe operations as sequential processes, many operations may be performed in parallel or simultaneously. Furthermore, the order of operations may be reordered. A process terminates when its operations are complete, but it may have additional steps not shown in the diagrams. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. If a process corresponds to a function, its termination may correspond to the function's return to the calling function or main function.
[0046] The processes and / or operations shown in Figures 3 to 5 may be implemented by software (e.g., code, instructions, programs), hardware, or a combination thereof, executed by one or more processing units (e.g., processor cores). The software may be stored in memory (e.g., on a memory device, on a non-temporary computer-readable storage medium). The specific sequence of processing steps in Figures 3 to 5 is not intended to be limiting. Other sequences of steps may be performed according to alternative embodiments. For example, in alternative embodiments, the steps outlined above may be performed in a different order. Furthermore, the individual steps illustrated in Figures 3 to 5 may include multiple substeps that may be performed in various sequences as appropriate for the individual steps. Moreover, additional steps may be added or removed depending on the particular application. Those skilled in the art will recognize many variations, modifications, and substitutions.
[0047] Figure 3 is a high-level block diagram of process 300 for service orchestration within a distributed pod-based system according to various aspects of this disclosure. The process shown in Figure 300 is implemented by the architecture, system, and technology shown in Figures 1 and 2.
[0048] In block 305, image templates are configured for various types of sub-services or services to be deployed. An image template is constructed using a script of instructions that defines how to build a particular image template. The script of instructions may be written by a user, such as a software deployment service administrator or a software developer attempting to deploy a given type of sub-service or service, based on the service hardware requirements. Types of sub-services or services include, but are not limited to, modeling software such as machine learning models, regression models, or any other type of supervised or unsupervised model; SAMD; software that works in conjunction with physical medical devices; and data acquisition and processing software (e.g., stream processing, batch processing, long-running services, data analysis and processing, data storage, etc.). Furthermore, these categories are not mutually exclusive; for example, a SAMD application may include a machine learning model or a data acquisition and processing aspect. Each image template is a binary containing metadata describing all the requirements for running a single container for a certain type of sub-service or service, as well as the needs and capabilities of the container. The template image is used to build a container for running one or more programs to provide a type of sub-service or service. Thus, each container is essentially an execution image of one or more programs. However, the image template on which a container is built exists separately and cannot be modified. When a container is built using an image template, a read-and-write copy of the requirements for running the container (e.g., resources specified for a subservice or service) is created within the container. Once a container is built, it adds a writable layer on top of the immutable template image, meaning that the template image can be modified to include the source code, libraries, dependencies, tools, and other files necessary to run one or more programs in order to provide a subservice or service.An unlimited number of images for running one or more programs can be created from a single image template.
[0049] In block 310, an image template is hardened based on the type of sub-service or service in which the image template is configured for deployment. Hardening is the process of configuring an image according to security best practices to reduce the image's vulnerabilities (e.g., hardening a software package to reduce exposures and attack vectors using different tools and configurations). Security best practices are independent of the cloud service provider and can be configured independently for the type of sub-service or service in which the image template is configured for deployment. For example, a first set of security best practices may be defined to harden an image template configured for data analysis and processing. The first set of security best practices takes into account commonly seen vulnerabilities with respect to data analysis and processing. Furthermore, a second set of security best practices may be defined to harden an image template configured for SAMD. The second set of security best practices takes into account commonly seen vulnerabilities with respect to SAMD. Furthermore, a third set of security best practices may be defined to harden an image template configured for artificial intelligence or machine learning processing. The third set of security best practices takes into account commonly seen vulnerabilities with respect to artificial intelligence or machine learning processing. While Figure 3 shows only three types of hardening processes, it should be understood that multiple additional or alternative hardening processes may be available for hardening image templates, including stream process hardening and batch process hardening.
[0050] In block 315, the hardened image template is tailored based on the type of subservice or service in which the image template is configured for deployment. Tailoring is the process of configuring the image according to image specifications to optimize the deployment workflow and performance (e.g., improving resource usage such as execution time, memory usage, disk space usage, and network usage). Image specifications are independent of the cloud service provider and can be configured independently for the type of subservice or service in which the image template is configured for deployment. For example, a first set of image specifications may be defined to tailor an image template configured for stream processing. This first set of image specifications takes into account commonly observed behaviors and problems with respect to stream processing. Furthermore, a second set of image specifications may be defined to tailor an image template configured for input / output processing. This second set of image specifications takes into account commonly observed behaviors and problems with respect to input / output processing. Furthermore, a third set of image specifications may be defined to tailor an image template configured for network processing. This third set of image specifications takes into account commonly observed behaviors and problems with respect to network processing. While Figure 3 shows only three types of tuning processes, it should be understood that multiple additional or alternative tuning processes, including batch process tuning and long-running service tuning, may be available for tuning image templates.
[0051] In block 320, the (hardened and / or tuned) image template is registered in the registry. The registry provides services for storing and retrieving images to one or more repositories (i.e., image artifact factories). Each repository contains one or more image templates (hardened and / or tuned).
[0052] In Block 325, the actor releases the source code for verification, validation, and deployment to a CI / CD system of the software platform (e.g., the government regulatory entity's digital health platform 100 as described in Figure 1). In various cases (e.g., when the actor is a third-party developer or partner), the source code has already been validated according to the quality management system (QMS) associated with each actor. For example, each actor may establish a software lifecycle model for validating software developed within a QMS framework appropriate to its product and organization. A QMS is a set of interrelated or interacting elements such as policies, objectives, procedures, processes, and resources established individually or collectively to guide the organization. For each software lifecycle activity, there are actionable tasks that support the conclusion that the software is validated. However, the tasks to be performed, their order of execution, and the iteration and timing of their execution are determined by the specific software lifecycle model chosen and the safety risks associated with the software application as individually perceived by the actor. Each task for validating the software typically begins, for example, with requirements for each function of the software, and the actor must be able to point to the requirements that describe the function. Furthermore, for each requirement, the actor should have a plan to test its functionality to ensure it can function as needed, and a record-keeping system to record evidence that the plan was executed and the results of the tests. Once the source code has been reviewed and verified in accordance with the actor's QMS, the actor may release the source code to the CI / CD system for review, verification, and deployment in accordance with the software platform's QMS.
[0053] In block 330, the software platform's CI / CD system receives the source code and automatically performs quality and compliance checks on the source code and executable program in accordance with the QMS associated with the software platform. A determination is then made as to whether the source code and executable program are valid and / or contain vulnerabilities due to open source. If the source code and executable program are invalid (do not meet all or part of the QMS requirements) and / or contain vulnerabilities due to open source (as defined and determined by the software platform in accordance with the QMS), the CI / CD system forwards the source code back to the actor to correct the defects and / or vulnerabilities. Conversely, if the source code and executable program are valid (meet all or part of the QMS requirements) and / or do not contain vulnerabilities due to open source (as defined and determined by the software platform in accordance with the QMS), the CI / CD system notifies the kernel to begin the deployment process for a subservice or service using the source code or software.
[0054] In block 335, the kernel (for example, kernel 200 as described in Figure 2) receives a request to start a deployment process for a subservice or service using source code or software. The kernel is deployed in a distributed computing environment.
[0055] In block 340, the kernel parses the request to identify the type of subservice or service to be deployed, as well as the source code, libraries, dependencies, tools, and other files necessary to run one or more programs to provide the subservice or service. The type of subservice or service may include, but is not limited to, modeling software such as machine learning models, regression models, or any other type of supervised or unsupervised model; SAMD; software that works in conjunction with physical medical devices; or data ingestion and processing software (e.g., stream processing, batch processing, long-running services, data analysis and processing, data storage, etc.). For a subservice or service to be deployed in a distributed computing environment, the type of subservice or service must be configured to be supported by the distributed computing environment. The kernel checks the type of subservice or service to be deployed against the types of subservices or services supported by the distributed computing environment. If the type of subservice or service is not configured to be supported by the distributed computing environment, the kernel forwards the request to a different kernel on a different distributed computing environment that may be configured to support that type of subservice or service. Therefore, the distributed computing environment that the kernel ultimately identifies as being configured to support its subservice or type of service may be the same as or different from the distributed computing environment running the kernel that first receives the request for the subservice or service.
[0056] In block 345, if the subservice or service type is configured to be supported by the distributed computing environment, the kernel retrieves an image for provisioning the specified resources within the deployment ring of the distributed computing environment. The image is retrieved from one or more repositories using the registry described in block 320. The image is a template for a software package that contains the specifications of the resources used to run the software package, and the template is customized to use the resources based on the type of the first part of the service being deployed. For example, if the SAMD subservice is deployed, the kernel retrieves an image template configured for SAMD processing.
[0057] In block 350, the kernel requests resources available within the placement ring. The available resources within the placement ring are parsed, and based on the parsing of the available resources, a decision is made as to whether all of the specified resources from the image are available within the placement ring.
[0058] In block 355, if all of the specified resources from the image are available in the placement ring, the kernel initiates a build and deployment process that uses the image to build one or more containers that encapsulate the specified resources. If not all of the specified resources from the image are available in the placement ring, the kernel initiates an autoscaling process to scale up the available resources based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The kernel then initiates a build and deployment process that uses the image to build one or more containers that encapsulate the available and additional resources. Once the one or more containers are built, they add a writable layer on top of the image and modify it to include source code, libraries, dependencies, tools, and other files necessary to run one or more programs to provide a subservice or service. The one or more containers are wrapped into a single pod instance to run one or more programs to provide a subservice or service. The subservice or service is deployed using the single pod instance and one or more replicas of the modified image.
[0059] In block 360, a sub-service or service is exposed, and security for the sub-service or service is initiated. Security includes (i) authentication / authorization processes for identity and access control, and (ii) authentication / authorization processes and monitoring of the use of the sub-service or service for vulnerability concerns.
[0060] Figure 4 illustrates process 400, which uses the kernel to deploy a subservice or service onto a software platform. The process shown in flowchart 400 is implemented using the architecture, system, and technology shown in Figures 1 and 2.
[0061] In step 405, the CI of the software development system retrieves the source code for deployment and executes the build process to construct the executable program. As part of the build process, the CI of the software development system tests and verifies the source code and executable program in accordance with the QMS of the software development system. The QMS defines a set of requirements for verifying the source code to be suitable for the release manager's products and organization. For example, the set of requirements may be defined to determine whether the source code is suitable for its intended use, functions as intended to implement its intended use, and meets base-level security requirements. As an additional part of the build process, the CI of the software development system checks the quality of the source code. Code quality checks include checks for reliability (e.g., determining whether the code functions as intended with minimal defects), integrity (e.g., adhering to a consistent structure / style, being easy to understand, being documented, etc.), and testability (e.g., how well the software supports testing efforts for verification / verification). A decision is then made as to whether the source code and executable program are valid and / or of sufficient quality. If the source code and executable program are invalid (fail to meet all or part of the QMS requirements) and / or of poor quality (as defined and measured by the software development system in accordance with the QMS), the CI of the software development system will transfer the source code back to the development team to correct the defects and / or quality issues. In contrast, if the source code and executable program are valid (fail to meet all or part of the QMS requirements) and / or of good quality (as defined and measured by the software development system in accordance with the QMS), the CI of the software development system will suspend the release of the source code to the software platform.
[0062] In step 410, the software platform's CI / CD system receives the source code. In some cases, the entity controlling the CI / CD system may be the same as or different from the entity controlling the software development system.
[0063] In step 415, the CI / CD system executes the build process to build an executable program based on the received source code. As part of the build process, the CI / CD system tests and verifies the source code and executable program in accordance with the software platform's QMS. The QMS defines a set of requirements for verifying source code suitable for the software platform. For example, the set of requirements may be defined to determine whether the source code functions as intended to implement its intended use, meets an enhanced level of security, meets requirements enforced by international, national, and / or regional regulations, addresses data privacy concerns, and meets performance requirements specific to the container and software platform environment. As an additional part of the build process, the CI / CD system whitesources the source code. Whitesources include identifying the open-source features of the source code, determining the permissions or licenses associated with the open-source features, and compiling the permissions or licenses and associated open-source features into data structures. Subsequently, a determination is made as to whether the source code and executable program are valid and / or contain vulnerabilities due to open source. If the source code and executable program are invalid (fail to meet all or part of the QMS requirements) and / or contain vulnerabilities attributable to open source (as defined and determined by the software platform in accordance with the QMS), the CI / CD system will transfer the source code back to the development team to fix the source code defects and / or vulnerabilities. In contrast, if the source code and executable program are valid (fail to meet all or part of the QMS requirements) and / or do not contain vulnerabilities attributable to open source (as defined and determined by the software platform in accordance with the QMS), the CI / CD system will proceed with the source code or software deployment process.
[0064] In step 420, the kernel (for example, kernel 200 as described in Figure 2) receives a request to start a deployment process for a subservice or service using source code or software. The kernel is deployed to a distributed computing environment (which is part of a software platform).
[0065] In step 425, the kernel parses the request to identify the type of subservice or service to be deployed, as well as the source code, libraries, dependencies, tools, and other files necessary to run one or more programs to provide the subservice or service. The type of subservice or service may include, but is not limited to, modeling software such as machine learning models, regression models, or any other type of supervised or unsupervised model; SAMD; software that works in conjunction with physical medical devices; or data ingestion and processing software (e.g., stream processing, batch processing, long-running services, data analysis and processing, data storage, etc.). For a subservice or service to be deployed in a distributed computing environment, the type of subservice or service must be configured to be supported by the distributed computing environment. The kernel checks the type of subservice or service to be deployed against the types of subservices or services supported by the distributed computing environment. If the type of subservice or service is not configured to be supported by the distributed computing environment, the kernel forwards the request to a different kernel on a different distributed computing environment that may be configured to support that type of subservice or service.
[0066] In step 430, if the sub-service or service type is configured to be supported by the distributed computing environment, the kernel requests available resources from a placement constraint process running across one or more placement rings in the distributed computing environment. Each placement ring may contain a pre-integrated and optimized combination of one or more types of resources. In a particular example, different placement rings may be pre-provisioned for different types of cloud services. For example, a first set of placement rings may be provisioned for a SAMD service, and a second set of placement rings may contain a different combination of resources than the first set of placement rings and may be provisioned for a data analytics service, for example.
[0067] In step 435, the placement constraint process parses the available resources on one or more placement rings in the distributed computing environment. The parsing is performed to obtain a list of all available resources on one or more placement rings in the distributed computing environment.
[0068] In step 440, the placement constraint process makes a decision based on parsing the available resources whether all of the specified resources from the image are available in the placement ring. Images are obtained from image artifact factories (one or more repositories) based on the type of subservice or service. An image is a template for a software package that contains the specifications of the resources used to run the software package, and the template is customized to use the specified resources based on the type of subservice or service. If all of the specified resources from the image are available in one or more placement rings, the placement constraint process reserves the specified resources and notifies the kernel that the specified resources are available and reserved. If not all of the specified resources from the image are available in the placement rings, the placement constraint process auto-scales the available resources based on the image to provide additional resources to one or more placement rings to satisfy the specified resources identified from the image. The placement constraint process then reserves the specified resources and notifies the kernel that the specified resources are available and reserved.
[0069] In step 445, the kernel requests the deployment of a subservice or service via the orchestration engine. The request includes information about the location of a specified resource within one or more deployment rings, an image associated with the type of subservice or service to be deployed, and the source code, libraries, dependencies, tools, and other files required to run one or more programs to provide the subservice or service.
[0070] In step 450, the orchestration engine detects the type of orchestration to be performed for the deployment of a subservice or service. The type of orchestration involves identifying the type of orchestration from several types of orchestrations based on the type of subservice or service.
[0071] In step 455, the orchestration engine uses the image to build one or more containers that encapsulate the resources specified based on the type of orchestration for the deployment of the subservice or service. Once the one or more containers are built, they add a writable layer on top of the image and modify it to include source code, libraries, dependencies, tools, and other files necessary to run one or more programs to provide the subservice or service. The one or more containers are wrapped into a single pod instance to run one or more programs to provide the subservice or service. The subservice or service is deployed using the single pod instance and one or more replicas of the modified image. The orchestration engine then notifies the kernel whether the deployment of the subservice or service was successful or unsuccessful (and why).
[0072] In step 460, if the deployment fails, the kernel notifies the CI / CD system so that corrective actions can be taken. If the deployment is successful, the kernel performs a health check to evaluate the functionality of the subservice or service and determine whether the subservice or service is functioning as expected. If the service is not functioning as expected, the kernel notifies the CI / CD system that the service is not functioning as expected.
[0073] In step 465, when the service is functioning as expected, the kernel (i) exposes a subservice or service (for example, registers a subservice or service for use by one or more subscribers or users), (ii) initiates security for the subservice or service, and (iii) notifies the CICD system of the service's success in order to function as expected. Security includes (i) authentication / authorization processes for identity and access control, and (ii) authentication / authorization processes and monitoring of the use of the subservice or service for vulnerability concerns.
[0074] Figure 5 shows a process 500 for deploying one or more sub-services of a service on a software platform. In step 505, a first request is received in a first kernel residing in a first distributed computing environment. The first request is to initiate the deployment process for a first sub-service of the service on the first distributed computing environment. The first sub-service has a type, and for the first sub-service to be deployed on the first distributed computing environment, the type of the first sub-service must be configured to be supported by the first distributed computing environment. To be configured to support means that the distributed computing environment provides computing power, memory storage, content delivery, and other capabilities to ensure that the type of sub-service runs and scales. In some cases, the type of the first sub-service may include, but is not limited to, modeling software such as machine learning models, regression models, or any other type of monitoring or non-monitoring model; software as a medical device; software that works in conjunction with a physical medical device; or data ingestion and processing software.
[0075] To ensure that the type of the first subservice is configured to be supported by the first distributed computing environment, the entity sending the request (e.g., a CI / CD system) determines the type of the first subservice, determines the types of subservices that are configured to be supported by multiple distributed computing environments, selects a given distributed computing environment (e.g., the first distributed computing environment) configured to support the type of the first subservice, and sends the request to the given distributed computing environment (e.g., the first distributed computing environment). Alternatively, to ensure that the type of the first subservice is configured to be supported by the first distributed computing environment, the entity sending the request (e.g., a CI / CD system) determines the type of the first subservice and sends a first request having the type of the first subservice. The first kernel checks the type of subservice to be deployed against the types of subservices supported by the first distributed computing environment. If the type of the first subservice is not configured to be supported by the first distributed computing environment, the first kernel forwards the request to a different kernel on a different distributed computing environment that may be configured to support the type of the first subservice. In contrast, if the type of the first subservice is configured to be supported by the first distributed computing environment, the process proceeds to step 510.
[0076] In step 510, in response to receiving a first request and the type of first subservice which is configured to be supported by the first distributed computing environment, the first kernel initiates the provisioning process for the specified resources within the deployment ring of the first distributed computing environment. The provisioning process includes obtaining an image based on the type of first subservice. An image is a template for a software package that contains the specifications of the resources used to run the software package, and the template is customized to use the specified resources based on the type of first subservice. Obtaining an image includes identifying an image from multiple images based on the type of first subservice. The image is configured in accordance with security best practices to mitigate image vulnerabilities, and security best practices are selected based on the type of first subservice. In some cases, the image is further configured in accordance with image specifications to optimize the deployment workflow and performance, and image specifications are selected based on the type of first subservice.
[0077] The provisioning process further includes placing specified resources within the placement ring, which includes parsing the image to identify the specified resources, requesting available resources from the placement ring, parsing the available resources from the placement ring, and determining, based on the parsing of the available resources, whether all of the specified resources from the image are available within the placement ring. If not all of the specified resources from the image are available within the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. If all of the specified resources from the image are available within the placement ring, the specified resources are reserved.
[0078] The provisioning process further involves using the image to build one or more containers that encapsulate specified resources. These one or more containers are wrapped in a first pod to run one or more programs to provide a first sub-service. Once the one or more containers are built, the image is modified using a writable layer to include the source code necessary to run the one or more programs. In a particular case, the image is modified to include source code, libraries, dependencies, tools, and other files necessary to run the one or more programs to provide the first sub-service.
[0079] In step 515, the first subservice is deployed using one or more replicas of the first pod containing the provisioned specified resources and a modified image for the type of the first subservice. The first subservice is deployed to the first distributed computing environment.
[0080] In step 520, a health check is performed to evaluate the functionality of the first subservice and determine whether the first subservice is functioning as expected. The first subservice is functioning as expected if the source code and executable are valid (meeting all or part of the QMS requirements), the source code and executable do not contain open-source vulnerabilities (defined and determined by the software platform in accordance with the QMS), and / or the first subservice passes the health check. If the first subservice fails the health check, the CICD system is notified that the service is not functioning as expected. If the first subservice is functioning as expected, (i) the first subservice is made public, (ii) security for the first subservice is initiated, and (iii) the CICD system is notified of the success of the first subservice functioning as expected.
[0081] Optionally, if the first subservice is functioning as expected in step 525, the first subservice may be made available for use, and a user may initiate execution of the first subservice. Execution of the first subservice may include (i) the kernel master determining a framework for executing the first subservice based on the type of the first subservice or service, and (ii) the kernel master offering the framework available resources in the deployment ring to execute one or more programs to provide the first subservice, receiving information about a task defined by one or more programs in response to the offer, and the kernel master sending the task to a kernel agent that allocates the specified resources to the execution unit of the framework for executing the task.
[0082] As further shown in Figure 5, processes similar to those in steps 505-525 may be executed for the second, third, fourth, etc. (n) subservices of the service in parallel, substantially parallel, offset, or sequentially with the processes executed for each other and for the first subservice. These processes may be executed to deploy all or some of the subservices related to the service deployed on a software platform across multiple distributed computing environments, in accordance with aspects of this disclosure.
[0083] Viewed. Further consideration. Some embodiments of this disclosure include a system comprising one or more data processors. In some embodiments, the system includes a non-temporary, machine-readable storage medium containing instructions that, when executed on one or more data processors, cause one or more data processors to execute some or all of the methods and / or some or all of the processes disclosed herein. Some embodiments of this disclosure include a computer program product tangibly embodied in a non-temporary, machine-readable storage medium containing instructions configured to cause one or more data processors to execute some or all of the methods and / or some or all of the processes disclosed herein.
[0084] The terms and expressions used are for illustrative purposes only, not limitation, and in using such terms and expressions, there is no intention to exclude any equivalent or part of any of the features shown and described, however it should be recognized that various modifications are possible within the scope of the invention described in the claims. Accordingly, although the invention described in the claims is specifically disclosed by embodiments and optional features, modifications and variations of the concepts disclosed herein may be relied upon by those skilled in the art, and it should be understood that such modifications and variations are considered to be within the scope of the invention as defined by the appended claims.
[0085] The subsequent description provides only preferred exemplary embodiments and is not intended to limit the scope, applicability, or configuration of the Disclosure. Rather, the subsequent description of preferred exemplary embodiments provides possible descriptions for implementing various embodiments for those skilled in the art. It will be understood that various modifications can be made to the function and arrangement of the elements without departing from the spirit and scope set forth in the appended claims.
[0086] Specific details are given in the following description to provide a complete understanding of the embodiments. However, it will be understood that embodiments can be carried out without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the embodiments with unnecessary detail. In other examples, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail to avoid obscuring the embodiments. Furthermore, this disclosure includes embodiments relating to the following clauses. [Clause 1] A computer implementation method, Receiving a first request in a first kernel present in a first distributed computing environment to initiate a deployment process for a first sub-service or service on the first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service; Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, Computer implementation methods, including those mentioned above. [Clause 2] The allocation of the aforementioned resources To analyze the image in order to identify the specified resource, Requesting available resources from the aforementioned placement ring, The parsing of the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The computer implementation method described in Clause 1, including the method described in Clause 1. [Clause 3] Acquiring the image further includes identifying the image from a plurality of images based on the type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The computer implementation method described in Clause 1 or 2, wherein the best security practice is selected based on the type of the first sub-service or service. [Clause 4] The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The computer implementation method according to Clause 3, wherein the image specification is selected based on the type of the first sub-service or service. [Clause 5] The computer implementation method according to any one of Clauses 1 to 4, wherein the aforementioned type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software. [Clause 6] The kernel further includes executing the first sub-service or service, and the execution of The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, The computer implementation methods described in Clause 5, including the computer implementation methods described in Clause 5. [Clause 7] The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, A computer implementation method as described in any one of clauses 1 to 6, further including the following: [Clause 8] The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system, notifying the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. When the first sub-service or service is functioning as expected, (i) the kernel exposes the first sub-service or service; (ii) the kernel initiates security for the first sub-service or service; and (iii) the CICD system is notified that the first sub-service or service has successfully functioned as expected. A computer implementation method as described in any one of clauses 1 to 7, further including the following: [Clause 9] Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, A computer implementation method as described in any one of clauses 1 to 8, further including the following: [Clause 10] It is a system, One or more data processors, A non-temporary computer-readable storage medium containing instructions, wherein when the instructions are executed on the one or more data processors, the one or more data processors... Receiving a first request in a first kernel present in a first distributed computing environment to initiate a deployment process for a first sub-service or service on the first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service; Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, A non-temporary computer-readable storage medium that enables the execution of an operation, A system equipped with these features. [Clause 11] The allocation of the aforementioned resources To analyze the image in order to identify the specified resource, Requesting available resources from the aforementioned placement ring, The parsing of the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The system described in Clause 10, including the system described in Clause 10. [Article 12] Acquiring the image further includes identifying the image from a plurality of images based on the type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The system described in Clause 10 or 11, wherein the best security practice is selected based on the type of the first sub-service or service. [Clause 13] The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The system according to Clause 12, wherein the image specification is selected based on the type of the first sub-service or service. [Clause 14] The system described in any one of the clauses 10 to 13, wherein the aforementioned type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software. [Article 15] The operation further includes the kernel executing the first sub-service or service, and the execution of The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, The systems described in Clause 14, including those mentioned above. [Clause 16] The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, The systems described in any one of clauses 10 to 15, further including the systems described in any one of clauses 10 to 15. [Article 17] The aforementioned operation, The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system, notifying the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. When the first sub-service or service is functioning as expected, (i) the kernel exposes the first sub-service or service; (ii) the kernel initiates security for the first sub-service or service; and (iii) the CICD system is notified that the first sub-service or service has successfully functioned as expected. The systems described in any one of clauses 10 to 16, further including the systems described in any one of clauses 10 to 16. [Clause 18] The aforementioned operation, Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, The systems described in any one of the clauses 10 to 17, further including the systems described in any one of the clauses 10 to 17. [Article 19] A computer program product tangibly embodied in a non-temporary machine-readable storage medium, which includes instructions configured to cause one or more data processors to perform an operation, wherein the operation is Receiving a first request in a first kernel present in a first distributed computing environment to initiate a deployment process for a first sub-service or service on the first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service; Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, Computer program products, including [this]. [Clause 20] The allocation of the aforementioned resources To analyze the image in order to identify the specified resource, Requesting available resources from the aforementioned placement ring, The parsing of the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. Computer program products as described in Clause 19, including: [Article 21] Acquiring the image further includes identifying the image from a plurality of images based on the type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The computer program product described in Clause 19 or 20, wherein the best security practices described above are selected based on the type of the first sub-service or service described above. [Article 22] The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The computer program product described in Clause 21, wherein the image specification is selected based on the type of the first sub-service or service. [Article 23] The computer program product described in any one of the clauses 19 to 22, wherein the aforementioned type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software. [Article 24] The operation further includes the kernel executing the first sub-service or service, and the execution of The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, Computer program products as described in Clause 23, including: [Article 25] The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, Computer program products as described in any one of clauses 19 to 24, including, further. [Article 26] The aforementioned operation, The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system, notifying the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. When the first sub-service or service is functioning as expected, (i) the kernel exposes the first sub-service or service; (ii) the kernel initiates security for the first sub-service or service; and (iii) the CICD system is notified that the first sub-service or service has successfully functioned as expected. Computer program products as described in any one of clauses 19 to 25, further including: [Article 27] The aforementioned operation, Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, Computer program products as described in any one of clauses 19 to 26, further including:
Claims
1. A computer implementation method, Receiving a first request to initiate a deployment process for a first sub-service or service on a first distributed computing environment in a first kernel present in a first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system to notify the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. Computer implementation methods, including those mentioned above.
2. The allocation of the aforementioned resources To analyze the image in order to identify the specified resource, Requesting available resources from the aforementioned placement ring, Parsing the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The computer implementation method according to claim 1, including the method described in claim 1.
3. Acquiring the aforementioned image further includes identifying the aforementioned image from a plurality of images based on the aforementioned type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The computer implementation method according to claim 1 or 2, wherein the best security practice is selected based on the type of the first sub-service or service.
4. The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The computer implementation method according to claim 3, wherein the image specification is selected based on the type of the first sub-service or service.
5. The computer implementation method according to any one of claims 1 to 4, wherein the type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software.
6. The kernel further includes executing the first sub-service or service, and the execution of The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, The computer implementation method according to claim 5, including the method described in claim 5.
7. The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, A computer implementation method according to any one of claims 1 to 6, further comprising:
8. A computer implementation method according to any one of claims 1 to 6, further comprising: (i) exposing the first sub-service or service by the kernel when the first sub-service or service is functioning as expected; (ii) initiating security for the first sub-service or service by the kernel; and (iii) notifying the CICD system that the first sub-service or service has successfully functioned as expected.
9. Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, A computer implementation method according to any one of claims 1 to 8, further comprising:
10. It is a system, One or more data processors, A non-temporary computer-readable storage medium containing instructions, wherein when the instructions are executed on one or more data processors, the one or more data processors: Receiving a first request to initiate a deployment process for a first sub-service or service on a first distributed computing environment in a first kernel present in a first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system to notify the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. A non-temporary computer-readable storage medium that enables the execution of an operation, A system that includes these features.
11. The allocation of the aforementioned resources Analyzing the image to identify the specified resource, Requesting available resources from the aforementioned placement ring, Parsing the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The system according to claim 10, including the following:
12. Acquiring the aforementioned image further includes identifying the aforementioned image from a plurality of images based on the aforementioned type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The system according to claim 10 or 11, wherein the best security practice is selected based on the type of the first sub-service or service.
13. The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The system according to claim 12, wherein the image specification is selected based on the type of the first sub-service or service.
14. The system according to any one of claims 10 to 13, wherein the type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software.
15. The operation further includes the kernel executing the first sub-service or service, and the execution is The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, The system according to claim 14, including the system described in claim 14.
16. The operation described above is The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, The system according to any one of claims 10 to 15, further comprising:
17. The system according to any one of claims 10 to 15, wherein the operation further includes (i) exposing the first sub-service or service by the kernel when the first sub-service or service is functioning as expected, (ii) initiating security for the first sub-service or service by the kernel, and (iii) notifying the CICD system that the first sub-service or service has successfully functioned as expected.
18. The aforementioned operation, Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, The system according to any one of claims 10 to 17, further comprising:
19. A computer program for causing one or more data processors to perform an operation, wherein the operation is Receiving a first request to initiate a deployment process for a first sub-service or service on a first distributed computing environment in a first kernel present in a first distributed computing environment, wherein the first sub-service or service has a type, and the type of the first sub-service or service must be configured to be supported by the first distributed computing environment in order for the first sub-service or service to be deployed on the first distributed computing environment; In response to receiving the request and the type of the first sub-service or service that the first distributed computing environment is configured to support, the first kernel provisions a specified resource within the deployment ring of the first distributed computing environment, wherein the provisioning is Acquiring an image based on the type of the first sub-service or service, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the type of the first sub-service or service, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a first pod for running one or more programs to provide the first sub-service or service, Provisioning specified resources within the deployment ring of the first distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The first kernel deploys the first sub-service or service using one or more replicas of the first pod and the modified image, The kernel performs health checks to evaluate the functionality of the first sub-service or service and to determine whether the first sub-service or service is functioning as expected. If the first sub-service or service fails the health check, the Continuing Integration and Continuous Deployment (CICD) system is notified that the first sub-service or service is not functioning as expected, and the first request is received from the CICD system to notify the Continuing Integration and Continuous Deployment (CICD) system that the first sub-service or service is not functioning as expected. A computer program that includes [this].
20. The allocation of the aforementioned resources Analyzing the image to identify the specified resource, Requesting available resources from the aforementioned placement ring, Parsing the available resources from the aforementioned arrangement ring, Based on the parsing of the available resources, determine whether all of the specified resources from the image are available within the placement ring. In response to the fact that not all of the specified resources from the image are available in the placement ring, the available resources are automatically scaled based on the image to provide the placement ring with additional resources to satisfy the specified resources identified from the image. The computer program according to claim 19, including the computer program described in claim 19.
21. Acquiring the aforementioned image further includes identifying the aforementioned image from a plurality of images based on the aforementioned type of the first sub-service or service, The aforementioned image is configured in accordance with best security practices to mitigate vulnerabilities in the aforementioned image. The computer program according to claim 19 or 20, wherein the best security practice is selected based on the type of the first sub-service or service.
22. The aforementioned image is further configured according to the image specifications to optimize the deployment workflow and performance. The computer program according to claim 21, wherein the image specification is selected based on the type of the first sub-service or service.
23. The computer program according to any one of claims 19 to 22, wherein the type of the first sub-service or service is machine learning model software, software as a medical device, software that operates in conjunction with a physical medical device, or data acquisition and processing software.
24. The operation further includes the kernel executing the first sub-service or service, and the execution is The kernel master determines a framework for executing the first sub-service or service based on the type of the first sub-service or service, The master of the kernel offers the framework available resources in the deployment ring to run the one or more programs in order to provide the first sub-service or service, In response to the offer, the master of the kernel receives information about a task defined by one or more programs, The master of the kernel transmits the task to the kernel agent which allocates the specified resources to the execution unit of the framework for executing the task, The computer program according to claim 23, including the computer program described in claim 23.
25. The operation described above is The kernel exposes the first sub-service or service, The kernel initiates the security of the first sub-service or service, A computer program according to any one of claims 19 to 24, further comprising:
26. The computer program according to any one of claims 19 to 24, wherein the operation further includes (i) exposing the first sub-service or service by the kernel when the first sub-service or service is functioning as expected, (ii) initiating security for the first sub-service or service by the kernel, and (iii) notifying the CICD system that the first sub-service or service has successfully functioned as expected.
27. The aforementioned operation, Receiving a second request in a second kernel residing in a second distributed computing environment to initiate a deployment process for a second sub-service of the service on the second distributed computing environment, wherein the second sub-service has a type, and the type of the second sub-service or service must be configured to be supported by the second distributed computing environment in order for the second sub-service or service to be deployed on the second distributed computing environment; In response to receiving the aforementioned request, the second kernel provisions a specified resource within the deployment ring of the second distributed computing environment, wherein the provisioning is Acquiring an image based on the second sub-service or service of the type, wherein the image is a template of the software package including specifications for resources used to run the software package, and the template is customized to use the specified resources based on the second sub-service or service of the type, Placing the specified resources within the aforementioned placement ring, Using the aforementioned image, construct one or more containers that encapsulate the specified resources, wherein the one or more containers are wrapped in a second pod for running one or more programs to provide the second sub-service or service, Provisioning specified resources within the deployment ring of the second distributed computing environment, which includes modifying the image to include source code necessary to run one or more programs using a writable layer; The second kernel deploys the second sub-service or service using one or more replicas of the second pod and the modified image, A computer program according to any one of claims 19 to 26, further comprising:
28. A non-temporary machine-readable storage medium recording a computer program according to any one of claims 19 to 27.
Citation Information
Patent Citations
Method and cloud management node for automated application deployment - Patents.com
JP2019503535A
Container image verification device, container image verification method, and container image verification program
JP2020154861A