Container resource configuration method, computing resource access processing method and data system

By preloading modules in the server kernel space to divide virtual partitions and using NVMe SR-IOV technology to determine the binding relationship between the container's virtual partitions and namespaces, the problem of insufficient isolation and access performance of container computing resources on bare metal servers is solved, and secure and efficient configuration and access of computing resources are achieved.

WO2025243094A1PCT designated stage Publication Date: 2025-11-27CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Patent Information

Application Number
PCT/IB2025/053055
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-22
Filing Date
2025-03-24
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

In existing technologies, when containers are deployed on bare metal servers, there are problems with insufficient isolation of computing resources and access performance, especially in multi-user environments, which can easily lead to unauthorized access and security risks.

Method used

By preloading modules in the server kernel space to divide virtual partitions and using NVMe SR-IOV technology, the binding relationship between the virtual partitions and namespaces of the target container is determined, resource configuration files are generated, user space drivers are loaded, and direct configuration and access to computing resources are realized.

Benefits of technology

It improves the isolation and access performance of container resources, prevents unauthorized access, ensures secure direct access of target containers to computing resources, and enhances system stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025053055_27112025_PF_FP_ABST
    Figure IB2025053055_27112025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present disclosure are a container resource configuration method, a computing resource access processing method and a data system. The container resource configuration method comprises: determining a target virtual partition corresponding to a target computing resource of a target container; on the basis of the target virtual partition, querying a target namespace that has a binding relationship with the target virtual partition; acquiring a resource configuration file corresponding to the target namespace; and loading the target virtual partition and, on the basis of the resource configuration file, configuring the target computing resource of the target container. By means of namespaces and virtual partitions that have a binding relationship, the present disclosure binds the namespaces and computing resources and, on this basis, configures the computing resources, thus ensuring secure isolation of the computing resources of containers, effectively avoiding unauthorized access, ensuring direct and highly-efficient access of target containers to configured target computing resources, and improving the isolation and access performance of the container resources.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Container resource configuration method, computing resource access processing method and data system The present disclosure claims priority to Chinese Patent Application No. 202410645666.6, filed on May 22, 2024 with the Chinese Patent Office, entitled "Container resource configuration method, computing resource access processing method and data system", the entire contents of which are incorporated herein by reference. TECHNICAL FIELD The present disclosure relates to the field of virtualization technology, and in particular to a container resource configuration method, a computing resource access processing method and a data system. BACKGROUND With the development of virtualization technology, containers, as a lightweight virtualization technology, have changed software development, deployment and operation. Currently, container technology encapsulates application programs and their dependent environments into standardized units, which are run through computing resources on servers. However, a server often has multiple containers deployed thereon, and the containers have their respective computing resources. The configuration of container resources needs to consider the isolation and access performance between containers to avoid other users "illegally accessing" target computing resources of target containers, while at the same time, direct access (straight-through) of target containers to target computing resources is implemented as much as possible to improve isolation and access performance. SUMMARY In view of this, the present disclosure provides a container resource configuration method, a computing resource access processing method and a data system. One or more embodiments of the present disclosure also relate to a computing resource access processing method, a data system, a computing device, a computer-readable storage medium and a computer program product to solve the technical defects in the prior art. According to a first aspect of the present disclosure, a container resource configuration method is provided, comprising: determining a target virtual partition corresponding to a target computing resource of a target container; querying a target namespace having a binding relationship with the target virtual partition based on the target virtual partition; obtaining a resource configuration file corresponding to the target namespace; loading the target virtual partition and configuring the target computing resource of the target container based on the resource configuration file. According to a second aspect of the present disclosure, a computing resource access processing method is provided, comprising: receiving an access request for a target computing resource sent by a container engine of a user container, wherein the access request includes target verification information; verifying whether the user container has access rights to the target computing resource based on the target verification information and pre-generated initial verification information, wherein the target computing resource is configured using the container resource configuration method; in the case where the verification is passed, determining that the user container is the target container; starting the target container based on the target computing resource and allowing the target container to access the target computing resource.According to a third aspect of the present disclosure, a data system is provided, which comprises a target server and a container resource management unit, the target server comprising a target container, target computing resources and a computing resource controller; the computing resource controller is configured to determine a target virtual partition corresponding to the target computing resources of the target container, query a target namespace having a binding relationship with the target virtual partition based on the target virtual partition, and load the target virtual partition; and the container resource management unit is configured to receive a loading command of the target virtual partition issued by the computing resource controller, and configure the target computing resources of the target container based on the target virtual partition loaded by the computing resource controller. According to a fourth aspect of the present disclosure, a computing device is provided, which comprises a memory and a processor; the memory is configured to store computer programs / instructions, and the processor is configured to execute the computer programs / instructions, which realize the steps of the above method when executed by the processor. According to a fifth aspect of the present disclosure, a computer readable storage medium is provided, which stores computer programs / instructions, which realize the steps of the above method when executed by the processor. According to a sixth aspect of the present disclosure, a computer program product is provided, which comprises computer programs / instructions, which realize the steps of the above method when executed by the processor. In an embodiment of the present disclosure, a target virtual partition corresponding to target computing resources of a target container is determined; a target namespace having a binding relationship with the target virtual partition is queried based on the target virtual partition; a resource configuration file corresponding to the target namespace is obtained; and the target virtual partition is loaded, and the target computing resources of the target container are configured based on the resource configuration file. Through the namespace and the virtual partition having the binding relationship, the binding of the namespace and the computing resources is realized, and the computing resource configuration is completed on this basis, thereby ensuring the safe isolation of the computing resources of the container, effectively preventing illegal access, ensuring the direct and efficient access of the target container to the configured target computing resources, and improving the isolation and access performance of the container resources. BRIEF DESCRIPTION OF DRAWINGS Fig. 1 is a schematic diagram of a user account of a cloud computing resource; Fig. 2 is a schematic diagram of a management and control account of a management and control platform; Fig. 3 is a schematic diagram of an architecture of a data system; Fig. 4 is a schematic diagram of a container resource configuration method; Fig. 5 is a flowchart of a container resource configuration method provided by an embodiment of the present disclosure; Fig. 6 is a schematic diagram of a container resource configuration method provided by an embodiment of the present disclosure; Fig. 7 is a flowchart of an access processing method of a computing resource provided by an embodiment of the present disclosure; Fig. 8 is a structural schematic diagram of a data system provided by an embodiment of the present disclosure; and Fig. 9 is a structural block diagram of a computing device provided by an embodiment of the present disclosure.DETAILED DESCRIPTION In the following description, numerous specific details are set forth to provide a thorough understanding of the present description. However, the present description can be practiced without the specific details. In other instances, well-known methods, procedures, components, and networks have not been described in detail so as not to unnecessarily obscure aspects of the present description. The terminology used in the description presented herein is not intended to be interpreted in any specific and / or limited manner. The terminology used in the present description is intended to be interpreted in accordance with the purposes of the present description as reflected in the specification, along with its attached drawings and its entirety. Moreover, the use of “for example,” “e.g.,” “such as,” or “among other” in reference to various examples, implementations, and embodiments of the present description indicates that alternative implementations and embodiments not explicitly described or shown are possible. It is intended that the description and examples presented herein be considered as non-limiting only. The terms “and”, “or”, and “and / or” as used herein can include a variety of both logical and arithmetic combinations to the associated endpoints including, but not limited to, one of, any number of, all of, etc. It is to be understood that the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. It is to be further understood that the terms “comprising”, “comprises” and “including”, “has” when used herein, specify the presence of stated features, integers, steps, operations, elements, or components but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof. The term “if can be interpreted to mean “when” or “upon” or “in response to determining” depending on the context. In addition, it is important to note that user information (including, but not limited to, user device information, user personal information, etc.) and data (including, but not limited to, data for analysis, stored data, displayed data, etc.) involved in one or more embodiments of the present description are all information and data authorized by the user or authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions, and provide corresponding operation interfaces for users to choose authorization or rejection. First, the terms involved in one or more embodiments of the present description are explained. Bare metal server: a physical server without any virtualization layer, on which users can directly run operating systems and applications, just like using independent servers in traditional data centers. runD: runD secure container, providing a secure container engine that seamlessly integrates with the standard container ecosystem, allowing users to use cloud-native ecosystems while taking advantage of the isolation capabilities of secure containers. Peripheral Component Interconnect Express (PCIe): a high-speed serial computer expansion bus standard used to connect motherboards and other computing resources to achieve efficient data access.Non-Volatile Memory Express (NVMe): A storage access protocol designed specifically for use with non-volatile storage, providing a low-latency, high-bandwidth interface to fully utilize the performance potential of non-volatile storage. Peripheral Component Interconnect Express Virtual Function (PCIe VF): A virtualization technology for PCIe computing resources, which divides a single computing resource into multiple virtual partitions, each appearing as an independent physical device for direct access by multiple virtual machines or containers. Peripheral Component Interconnect Express Physical Function (PCIe PF): The original, unvirtualized hardware resource on an Express computing resource, appearing as a complete, independent physical device interface for direct management by an operating system or hypervisor and use by a single or multiple applications. Physical functions serve as the basis for virtualization, responsible for managing and allocating their subordinate virtual functions to achieve efficient and isolated virtualization access to a single computing resource. Non-Volatile Memory Express (NVMe): A storage access protocol and interface standard designed specifically for non-volatile storage. It provides an efficient, low-latency communication mechanism to fully exploit the performance potential of storage devices based on flash memory or other new non-volatile storage technologies. Namespace (NVMe namespace): Namespace is a mechanism in the Non-Volatile Memory Express protocol (NVMe protocol) that logically divides and isolates NVMe devices (usually SSDs). Non-Volatile Memory Express Single Root I / O Virtualization (NVMe SR-IOV): A read-write virtualization technology based on the Non-Volatile Memory Express standard, which allows a single Non-Volatile Memory Express computing resource to be directly accessed by multiple virtual machines or containers and other virtual environments, while providing isolation and protection for each virtual environment. This technology uses the SR-IOV extension function of the PCIe bus to create multiple virtual partitions for physical devices, called virtual functions, and one or more physical functions.

[0002] K8S (Kubernetes) : an open-source container orchestration platform for automating deployment, scaling, and managing containerized applications. It provides a platform that enables users to define the deployment, configuration, updates, and maintenance of containerized applications in a declarative manner, ensuring that applications run efficiently, reliably, and scalably in a cluster environment across multiple host nodes. Task Definition Container (TDC) : a container resource management unit that serves as a front-end compute resource manager. Currently, to better address the use and operation of K8S and solve the complexity of resource and K8S fragmentation, K8S is used as a user interface for computing resource usage, providing cloud computing services for containers, and delivering a serverless mode, where users do not need to worry about the underlying node and cluster operation and management: the container computing service operation server (bare-metal server), and users only need to operate the target container on the server, without maintaining the server where the target container resides. As shown in FIG. 1, FIG. 1 shows a user account diagram of cloud computing resources: the container cloud disk includes a resource ownership account and a hosting account, where the resource ownership account is the user's platform account, and the hosting account is the user-authorized hosting account. At the same time, the container computing service manages the container cloud disk in a role-playing manner for customers, as shown in FIG. 2, FIG. 2 shows a management and control account diagram of a management and control platform: the service account of the container computing service is the user-authorized hosting account described in FIG. 1, including multiple resource accounts of the container computing service, and the service account of the container computing service is used to play the role of user calling the data interface of the container cloud disk, including creation, deletion, and query. However, such cross-account mounted project scenarios also pose security risks, such as the common Access Key (AK) leakage problem. FIG. 3 shows an architecture diagram of a data system, as shown in FIG. 3: on the bare-metal server, including multiple users' containers and container engines, for example, user A's container and container engine, user B's container and container engine, container platform (K8s), and container storage interface node plugin (CSI Node Plugin). The intelligent network card includes an application management unit and a container resource management unit. The network area includes a management and control platform.Wherein, the container and container engine of user A and the container and container engine of user B are areas that users can fully control, and the bare metal server is an area that users can break through, for example, a scenario of access password leakage, hacker escaping to the bare metal server, and the like, which can invade the computing resources of other users on the server, and are all defined as unsafe areas. Then, how to solve the data security problem between the container and container engine of the user and the server, realize the secure mounting of the computing resources, and ensure the isolation is a security challenge faced by the container computing service. In view of this problem, a feasible solution is that: the management and control platform manages and controls the mounting of the target computing resource to the server, is first hosted by a kernel component, and then is transferred to the container through a virtual partition device after the configuration of the target computing resource is completed. Fig. 4 shows a schematic diagram of a container resource configuration method, as shown in Fig. 4: Step 1: when the operating system of the bare metal server is started, a preloading module is loaded, each physical partition is divided into multiple virtual partitions, and the preloading module first hosts the multiple virtual partitions. For example, a preloading module sriov_controller.ko is pre-installed in the bare metal server, the module is loaded when the operating system of the bare metal server is started, each physical partition (physical function PCIe PF) is divided into 255 virtual partitions (virtual function PCIe VF), and the preloading module first hosts the 255 virtual partitions, so as to avoid that the unallocated virtual partition loads the kernel space driver virtio-pci / NVMe to access the back-end computing resource. Step 2: the container computing service creates and mounts the computing resource (front-end computing resource and back-end computing resource) to the bare metal server through a data interface, and uses a virtual partition hosting tool on the bare metal server to determine the virtual partition corresponding to the computing resource, loads the kernel space driver for the virtual partition, completes the resource configuration through the virtualization layer, and generates the block device in the secure container. For example, the container computing service creates and mounts the container cloud disk to the bare metal server through the data interface open api, and uses the virtual partition hosting tool vf-manager tool on the bare metal server to determine the corresponding virtual partition according to the serial number of the container cloud disk, loads the kernel space driver virtio-pci / NVMe for the virtual partition, completes the cloud disk configuration through the virtualization layer, and generates the block device in the secure container runD container. Step 3: the kernel space driver is unloaded, and the user space driver is loaded for the virtual partition.For example, the kernel space driver virtio-blk / NVMe driver is loaded with the user space driver vfio driver, and the computing resources (front-end computing resources and back-end computing resources) are directly passed to the block device of the secure container for loading. For example, the user space driver vfio directly passes the computing resources (front-end computing resources and back-end computing resources) to the secure container runD container for loading. The above method directly configures the computing resources of the container through the virtual partition technology, needs to install a preloading module in the kernel space of the server, preloads the virtual partition for the target container, and mounts the target computing resources to the target container after completing the configuration of the computing resources on the virtual partition, thereby improving the isolation and access performance of the container resources. However, the above method is invasive to the kernel of the bare metal server, needs to install a preloading module, and needs to modify a plurality of components, which is relatively large. In the present specification, a container resource configuration method is provided, and the present specification also relates to a computing resource access processing method, a data system, a computing device, a computer readable storage medium, and a computer program product, which are described in detail one by one in the following embodiments. Referring to FIG. 5, FIG. 5 shows a flowchart of a container resource configuration method provided by an embodiment of the present specification, including the following specific steps: step 502: determining a target virtual partition corresponding to a target computing resource of a target container. The present disclosure is applied to a system platform for configuring the computing resources of a container on a server. The container is a lightweight virtualization instance of an application program, and encapsulates the application program and its dependent environment into a standardized unit. A plurality of containers are often deployed on a server, and the plurality of containers share the kernel space of the operating system of the server (host), but each has an independent user space. The computing resource is a hardware resource supporting the running of an application program, including but not limited to a central processing unit (CPU), a memory, a disk storage, and a graphic processing unit (GPU). On the server, the computing resources are virtually divided into a plurality of containers, so that each container is as if running in an independent environment. The virtual partition is a virtual device created for the container to access the computing resources, the virtual partition is a plurality of virtual devices created for the computing resources, the virtual partition is an independent virtual device that can be allocated to the container for direct access, and the virtual partition has the configuration permission of the computing resources.For example, a plurality of NVMe virtual functions are created for the access of the PCIe computing resources by the containers through the NVMe SR-IOV technology. The target container is a container instance that needs to be configured with container resources. The target container is a container that encapsulates a specific application and its dependent environment into a standardized unit for deployment on a server. For example, in a K8s cluster, a target container that is running a database service needs to be configured with storage resources to ensure the stable operation of the database service and isolation from other containers. The target computing resource is a container resource of the target container that needs to be configured, including but not limited to: central processing unit, memory, disk storage, and graphics processing unit. For example, for the target container running the database service, the configuration parameters of the target computing resource are as follows: memory: 8 GB of RAM is allocated; SSD disk storage: 1 TB of SSD hard disk storage. The target virtual partition is a virtual device created for the access of the target computing resource by the target container. The target virtual partition behaves as an independent virtual device that can be allocated to the target container for direct access, and the target virtual partition has the configuration permission of the target computing resource. For example, a target virtual function PCIe VF10 is allocated to the target computing resource to determine the target virtual partition corresponding to the target computing resource of the target container. An optional way is to determine the target virtual partition corresponding to the target computing resource of the target container from a plurality of pre-created virtual partitions. For example, in response to a start instruction for starting a runD container as the target container, the target virtual function PCIe VF10 corresponding to the container cloud disk of the target container is determined from a plurality of pre-created virtual functions (PCIe VF1, PCIe VF2, and PCIe VF3) through the NVMe SR-IOV technology to determine the target virtual partition corresponding to the target computing resource of the target container. This lays a foundation for subsequent determination of the target namespace. Step 504: based on the target virtual partition, a target namespace having a binding relationship with the target virtual partition is queried. The namespace is an access address space used by a container to access a computing resource. The namespace is an access address space for a container to access a computing resource. The namespace is an access address space logically divided for a computing resource. For example, in a K8s cluster, each container has its exclusive namespace. The target namespace is an access address space used by the target container to access a computing resource. The target namespace is an access address space for the target container to access the target computing resource. The target namespace is an access address space logically divided for the target computing resource.For example, in a K8s cluster, a target container running a database service has an access address space for accessing computing resources, and storage resources can be accessed through the target namespace. The binding relationship between the virtual partition and the namespace is a pre-bound relationship between the virtual partition and the namespace, and the binding relationship between the namespace and the virtual partition is established by invoking the computing resource controller instruction. For example, in a K8s cluster, when configuring storage resources for a target container running a database service, the virtual function PCIe VF1 divided by the NVMe SR-IOV technology is pre-bound with the target namespace Namespace 1 (NVMe NS1) of the target container, and the binding relationship exists. Based on the target virtual partition, the target namespace that has a binding relationship with the target virtual partition is queried, and an optional way is to query the binding relationship between the namespace and the virtual partition based on the target virtual partition, and determine the target namespace that has a binding relationship with the target virtual partition. For example, based on the target virtual function PCIe VF1, the binding relationship between the namespace and the virtual function is queried, and the target namespace NVMe NS1 that has a binding relationship with the target virtual function PCIe VF1 is determined. Based on the target virtual partition, the target namespace that has a binding relationship with the target virtual partition is queried. This provides a basis for determining the resource configuration file corresponding to the target namespace. Step 506: Obtain the resource configuration file corresponding to the target namespace. The resource configuration file is a file recording the configuration parameters of the target computing resource, and the resource configuration file is pre-generated, for example, generated in the process of the container resource management unit executing the namespace attachment request (attach-namespace rpc call). After the resource configuration file is generated, a mapping relationship between the namespace and the resource configuration file is established. For example, the configuration file of the container cloud disk is as follows: apiVersion: vl kind: Persistent VolumeClaim metadata: name: database-pvc spec: accessModes:.

[0003] - ReadWriteOnce resources: requests: storage: ITi wherein, PersistentVolumeClaim defines the specification of the persistent storage resource required by the container: 1TB NVMe SSD, access mode: single container read-write Read Write Once. Obtain the resource configuration file corresponding to the target namespace, and one optional way is to: based on the resource configuration file information, query the mapping relationship between the namespace and the resource configuration file, and obtain the resource configuration file corresponding to the target namespace. Illustratively, based on the container cloud disk configuration file information, the mapping relationship between the namespace and the container cloud disk configuration file is queried, and the container cloud disk configuration file corresponding to the target namespace NVMe NS1 is obtained. Obtain the resource configuration file corresponding to the target namespace. Provide a configuration file support for subsequent configuration of the target computing resource. Step 508: load the target virtual partition, and configure the target computing resource of the target container based on the resource configuration file. Load the target virtual partition, and configure the target computing resource of the target container based on the resource configuration file, and one optional way is to: load the target virtual partition through the computing resource controller, and configure the target computing resource of the target container based on the resource configuration file. Illustratively, load the target virtual function PCIe VF1 through the NVMe controller, configure the container cloud disk of the target container based on the container cloud disk configuration file, and complete the opening of the container cloud disk. In the present disclosure, the target virtual partition corresponding to the target computing resource of the target container is determined; based on the target virtual partition, the target namespace having a binding relationship with the target virtual partition is queried; the resource configuration file corresponding to the target namespace is obtained; the target virtual partition is loaded, and the target computing resource of the target container is configured based on the resource configuration file. Through the namespace and the virtual partition having the binding relationship, the binding of the namespace and the computing resource is realized, and on this basis, the computing resource configuration is completed, which ensures the safe isolation of the computing resource of the container, effectively prevents illegal access, ensures the direct and efficient access of the target container to the configured target computing resource, and improves the isolation and access performance of the container resource. In one optional embodiment of the present disclosure, before step 506, the following specific steps are further included: obtain the configuration parameters of the target computing resource; and generate the resource configuration file of the target computing resource based on the configuration parameters. The configuration parameters of the target computing resource are attribute parameters used for configuring the target computing resource, including but not limited to: resource type, resource quota, resource limit, performance policy and access mode.For example, the resource types include the number of CPU cores, the memory capacity, the disk storage space, and the number of GPUs, the resource quotas include the CPU share, the memory limit, the disk quota, and the GPU video memory size, the resource limits include the CPU limit, the memory limit, the IOPS limit, and the bandwidth limit, the performance strategies include the priority when using the resource, the cache strategy, and the pre-fetch behavior, and the access modes include single-container read-write ReadWriteOnce, multi-container read-write ReadWriteMany, multi-container read-only ReadOnlyMany, and multi-container write-only WriteOnlyMany. oThe configuration parameters of the target computing resource are obtained, and an optional manner is to obtain the configuration parameters of the target computing resource through a remote procedure call. An optional manner is to obtain the configuration parameters of the target computing resource through a data interface. Based on the configuration parameters, the resource configuration file of the target computing resource is generated, and an optional manner is to generate the resource configuration file of the target computing resource based on the configuration parameters through a remote procedure call. An optional manner is to generate the resource configuration file of the target computing resource based on the configuration parameters through a data interface. Illustratively, the container computing service additional stage initiates a remote procedure call of namespace attachment (attach-namespace) to the container resource management unit through the management platform, wherein the remote procedure call includes the configuration parameters of the container cloud disk, the container resource management unit executes the remote procedure call of namespace attachment (attach-namespace), and only generates the configuration file of the container cloud disk, without actually completing the opening of the container cloud disk. The configuration parameters of the target computing resource are obtained, and the resource configuration file of the target computing resource is generated based on the configuration parameters. File support is provided for subsequent acquisition of the resource configuration file to complete container resource configuration. In an optional embodiment of the present specification, after the resource configuration file of the target computing resource is generated based on the configuration parameters, the following specific steps are further included: from a plurality of pre-divided namespaces, a corresponding target namespace is allocated to the resource configuration file, wherein the namespace is an address space logically divided for the computing resource. The plurality of pre-divided namespaces are address spaces logically divided for the computing resource, and any namespace is an access address space of the container for accessing the computing resource. For example, in a K8s cluster, a plurality of address spaces are obtained by logically dividing storage resources, and each container has its exclusive namespace. After the corresponding target namespace is allocated to the resource configuration file from the plurality of pre-divided namespaces, the following specific steps are further included: the mapping relationship between the namespace and the resource configuration file is determined and recorded. Illustratively, the storage resources are logically divided in advance to obtain three namespaces (NVMe NS1, NVMe NS2, and NVMe NS3), and the corresponding target namespace NVMe NS1 is allocated to the container cloud disk configuration file from the three namespaces. The mapping relationship between the namespace and the resource configuration file is determined and recorded: NVMe NS1-resource configuration file 1; NVMe NS2-resource configuration file 2; and NVMe NS3-resource configuration file 3.The target namespace is allocated to the resource configuration file from a plurality of pre-divided namespaces, wherein the namespace is an address space logically divided for the computing resources. The security isolation of the computing resources of the container is achieved. In an optional embodiment of the present specification, after the target namespace is allocated to the resource configuration file from a plurality of pre-divided namespaces, the following specific steps are further included: the target virtual partition corresponding to the target namespace is allocated from a plurality of pre-created virtual partitions, and the target namespace and the target virtual partition are bound, wherein the virtual partition is a virtual device with a configuration permission of the computing resources. The plurality of pre-created virtual partitions are virtual devices created for the container to access the computing resources, the virtual partition is a plurality of virtual devices created for the computing resources, and the virtual partition is an independent virtual device that can be directly accessed by the container. For example, in a K8s cluster, a plurality of address spaces are obtained by logically dividing the storage resources, and each container has its own namespace. The target virtual partition corresponding to the target namespace is allocated from a plurality of pre-created virtual partitions, and the target namespace and the target virtual partition are bound, and an optional way is that: the target virtual partition corresponding to the target namespace is allocated from a plurality of pre-created virtual partitions by a computing resource controller instruction, and the target namespace and the target virtual partition are bound, wherein the virtual partition is a virtual device provided by the computing resource controller to the container for directly accessing the target computing resources by the target container. Illustratively, in response to a start instruction of starting the runD container as the target container, the target virtual function PCIe VF1 corresponding to the target namespace NVMe NS1 is allocated from a plurality of virtual functions (PCIe VF1, PCIe VF2 and PCIe VF3) pre-created by the NVMe SR-IOV technology by calling the computing resource controller instruction nvme attach-ns, and the target namespace and the target virtual partition are bound, and the binding relationship NVMe NS1-PCIe VF1o is obtained. The target virtual partition corresponding to the target namespace is allocated from a plurality of pre-created virtual partitions, and the target namespace and the target virtual partition are bound, wherein the virtual partition is a virtual device with a configuration permission of the computing resources. The binding relationship between the target namespace and the target virtual partition is established, which lays a foundation for subsequent binding of the namespace and the computing resources. In an optional embodiment of the present specification, after step 508, the following specific steps are further included: starting the target container based on the target computing resources.Exemplarily, a running environment of the target container is configured based on a container cloud disk of the target container, a runD container, which is the target container, is started on the running environment of the target container, and the target container is started based on the target computing resource. The target container is started based on the target computing resource with high isolation and high access performance, which ensures high-performance running of the container and realizes effective management and isolation of the resource, prevents resource contention and waste, and improves overall stability and security of the system. In an optional embodiment of the present specification, before starting the target container based on the target computing resource, the following specific steps are further included: obtaining target verification information sent by a container engine of a user container; verifying whether the target container has access permission for the target computing resource based on the target verification information and pre-generated initial verification information; and determining that the user container is the target container in the case that the verification is passed. The user container is a container instance that requests to access the target computing resource. The user container may or may not be the target container, and therefore needs to be verified to ensure the isolation of the target computing resource. For example, on a server of a K8s cluster, two containers are deployed for two users to use, and both of the two containers are user containers. The container engine of the user container is a virtualization component for managing the user container, for example, a runD container engine of a secure container. The target verification information is verification permission information for verifying whether the user container has access to the target computing resource, including but not limited to a target computing resource identifier (diskID), a container identifier (such as a pod ID), and an access token (such as a token). For example, three-tuple information [disk ID, pod ID, token]. The initial verification information is standard permission information for verifying whether the user container has access to the target computing resource, including but not limited to a target computing resource identifier (diskID), a container identifier (such as a pod ID), and an access token (such as a token). For example, three-tuple information [disk ID, pod ID, token]. For the three-tuple information, the mounting relationship between the computing resource and the container is generated by the container computing service and delivered to the container resource management unit for management, the access token of the target computing resource is generated by the container resource management unit for management, and the access token of each target computing resource is different. An optional way of obtaining the target verification information sent by the container engine of the user container is to obtain the target verification information sent by the container engine of the user container through remote procedure call, and an optional way of obtaining the target verification information sent by the container engine of the user container is to obtain the target verification information sent by the container engine of the user container through a data interface.Exemplarily, the container computing service additional stage initiates, through the management platform, a remote procedure call of namespace attach-namespace to the container resource management unit, wherein the remote procedure call package target triplet information sent by the container engine of the user container, based on the target triplet information and the pre-generated initial triplet information, checks whether the target container has access permission to the container cloud disk, and in the case of passing the check, determines that the user container is the target container. Target verification information sent by the container engine of the user container is obtained; based on the target verification information and the pre-generated initial verification information, whether the target container has access permission to the target computing resource is checked; in the case of passing the check, it is determined that the user container is the target container. Through the check of the verification information, whether the user container has access permission to the target computing resource is determined, which further improves the security of the target computing resource. In an optional embodiment of the present specification, after checking whether the target container has access permission to the target computing resource based on the target verification information and the pre-generated initial verification information, the following specific steps are further included: in the case of failing the check, the target container is prohibited from starting. For example, the cloud disk of user B is accessed: after user A obtains the permission, the target computing resource can be unbound and bound, and when user A loads the target virtual partition corresponding to the cloud disk of user B, since user A does not hold the access token, the check cannot pass, the block device cannot be read and written, and the data on the cloud disk will not be leaked or tampered with, avoiding hacker escape. In the case of failing the check, the target container is prohibited from starting, and an optional way is: in the case of failing the check, it is determined that the user container is not the target container, and the target container is prohibited from starting. The target container can be prohibited from starting by modifying the access permission of the target container. Exemplarily, based on the target triplet information and the pre-generated initial triplet information, whether the target container has access permission to the container cloud disk is checked, and in the case of failing the check, it is determined that the user container is not the target container, and the target container is prohibited from starting. In the case of failing the check, the target container is prohibited from starting. Through the check of the verification information, whether the user container has access permission to the target computing resource is determined, and the starting of the target container is prohibited in time, which further improves the security of the target computing resource.In an optional embodiment of the present specification, before verifying whether the target container has access to the target computing resource based on the target verification information and the pre-generated initial verification information, the following specific steps are further included: obtaining the mounting relationship between the target container and the target computing resource; identifying whether there is a right to generate the initial verification information of the target container based on the mounting relationship between the target container and the target computing resource; and if so, generating the initial verification information of the target container. The mounting relationship between the container and the computing resource is an association relationship between the container and the computing resource for resource access, which is determined by the association relationship between the container and the namespace (the mapping relationship between the resource configuration relationship of the container and the namespace), the binding relationship between the namespace and the virtual partition, and the association relationship between the virtual partition and the computing resource. The mounting relationship ensures the direct access of the container to the computing resource. Based on the mounting relationship between the target container and the target computing resource, an optional way to identify whether there is a right to generate the initial verification information of the target container is to initiate a verification information update call instruction by an authorization service based on the mounting relationship between the target container and the target computing resource. Illustratively, the mounting relationship between the target container and the container cloud disk is obtained, a triple information update call instruction update-namespace initiated by the authorization service is used, whether there is a right to generate the initial triple information of the target container is identified based on the mounting relationship between the target container and the container cloud disk, and if so, the initial triple information of the target container is generated. The mounting relationship between the target container and the target computing resource is obtained, whether there is a right to generate the initial verification information of the target container is identified based on the mounting relationship between the target container and the target computing resource, and if so, the initial verification information of the target container is generated. This enhances the access control of the target computing resource, prevents unauthorized container startup or resource misuse, and further improves the security of the target computing resource. FIG. 6 shows a schematic diagram of a container resource configuration method according to an embodiment of the present specification. As shown in FIG. 6: Step ①: the container computing service initiates a namespace attachment request to the container resource management unit through the management and control platform management and control in the container storage interface attachment stage. For example, the container computing service initiates a namespace attachment request attach-namespace rpc call to the container resource management unit TDC through the management and control platform EBS management and control in the container storage interface mounting CSI attach stage. Step ②: the container resource management unit executes the namespace attachment request, does not really open a disk, only generates a resource configuration file of the cloud disk, and records the mapping relationship between the resource configuration file and the namespace.For example, the container resource management unit executes the namespace attachment request attach-namespace, does not actually open the disk, only generates the resource configuration file of the cloud disk, and records the mapping relationship between the resource configuration file and the namespace namespace. Step 3: A resource binding service is added in the container storage interface node plugin of the bare metal server, and the resource binding service is used to call the computing resource controller instruction to build the binding relationship between the namespace and the virtual service in the container storage interface mounting stage. The container resource management interface calls the container resource management unit to obtain the cloud disk configuration file information of the corresponding virtual partition. For example, a resource binding service CDA is added in the container storage interface node plugin CSI Plugin of the bare metal server, and the resource binding service CDA is used to call the computing resource controller instruction nvme attach-ns to build the binding relationship between the namespace and the virtual service in the container storage interface mounting stage. The container resource management interface calls the container resource management unit TDC to obtain the cloud disk configuration file information of the corresponding virtual partition PCIe VF. Step 4: The container resource management unit is called to authorize and update the triple information in the container storage interface mounting stage through the management platform management. For example, the container resource management unit TDC is called to authorize and update the triple information in the container storage interface mounting stage through the management platform EBS management. Step 5: The container engine starts the container, loads the corresponding virtual function through the computing resource driver to open the disk, and the resource configuration file obtained by the container resource management interface is completed to the container resource management unit to complete the front-end computing resource configuration and complete the opening of the disk. The computing resource driver loads the triple information check, and the container can be started based on the back-end computing resource only after the check is passed. For example, the container engine runD starts the container, loads the corresponding virtual function PCIe VF through the computing resource nvme driver to open the disk, and the resource configuration file obtained by the container resource management interface is completed to the container resource management unit TDC to complete the front-end computing resource configuration and complete the opening of the disk. The computing resource nvme driver loads the triple information check, and the container can be started based on the back-end computing resource only after the check is passed. Referring to FIG. 7, FIG. 7 is a flowchart of a computing resource access processing method provided in an embodiment of the present specification, including the following specific steps: Step 702: receiving an access request for a target computing resource sent by a container engine of a user container, wherein the access request includes target verification information.Step 704: verifying whether the user container has access to the target computing resource based on the target verification information and the pre-generated initial verification information, wherein the target computing resource is configured by using the container resource configuration method. Step 706: determining that the user container is the target container in the case of passing the verification. Step 708: starting the target container based on the target computing resource, and allowing the target container to make an access request to the target computing resource. The present disclosure is applied to a system platform that has access control over the computing resource of a container on a server. The access request to the target computing resource is a request for an instruction of the access permission of the initiated computing resource sent by the user container to the container engine, so as to obtain the access permission of the target computing resource, and to realize the access to the target computing resource in the running process of the user container. The present disclosure is based on the same inventive concept as the embodiment of the above description of FIG. 5, and the specific content is described above, which is not repeated here. In the present disclosure, the container engine receives the access request to the target computing resource sent by the user container, wherein the access request includes the target verification information; verifies whether the user container has access to the target computing resource based on the target verification information and the pre-generated initial verification information, wherein the target computing resource is configured by using the container resource configuration method; determines that the user container is the target container in the case of passing the verification; and starts the target container based on the target computing resource, and allows the target container to make an access request to the target computing resource. Through the binding of the namespace and the computing resource, the computing resource is configured, and when the computing resource is accessed, illegal access is effectively prevented, the direct and efficient access of the target container to the configured target computing resource is ensured, and the isolation and performance of the access are improved. In an optional embodiment of the present disclosure, after step 704, the following specific steps are further included: intercepting the access request in the case of failing the verification. The present disclosure is based on the same inventive concept as the embodiment of the verification information verification of the above description of FIG. 5, and the specific content is described above, which is not repeated here. The access request is intercepted in the case of failing the verification. Through the verification of the verification information, it is determined whether the user container has access to the target computing resource, the start of the target container is timely prohibited, the hacker escape is avoided, and the security of the target computing resource is further improved. In an optional embodiment of the present disclosure, before step 704, the following specific steps are further included: obtaining the mounting relationship between the target container and the target computing resource; identifying whether there is the permission of generating the initial verification information of the target container based on the mounting relationship between the target container and the target computing resource; and if not, the access request is intercepted.The embodiment of the disclosure generating the permission identification of the initial verification information of the target container is based on the same inventive concept as the above-mentioned Figure 5 description embodiment, and the specific content is referred to the above description, which will not be repeated here. Obtain the mounting relationship between the target container and the target computing resource; based on the mounting relationship between the target container and the target computing resource, identify whether it has the permission to generate the initial verification information of the target container; if not, intercept the access request. Identifying whether it has the permission to generate the initial verification information of the target container, timely prohibits the generation of the initial verification information of the target container, avoids the leakage of access password, and further improves the security of the target computing resource. Corresponding to the above method embodiment, the present specification also provides a data system embodiment, and Figure 8 shows a structural schematic diagram of a data system provided by an embodiment of the present specification. As shown in Figure 8, the system 800 includes a target server 810, the target server 810 includes a target container 8110, a target computing resource 8120, a computing resource controller 8130 and a container resource management unit 8140; the computing resource controller 8130 is configured to determine a target virtual partition corresponding to the target computing resource 8120 of the target container 8110, query a target namespace having a binding relationship with the target virtual partition based on the target virtual partition, and load the target virtual partition by driving; the container resource management unit 8140 is configured to receive a driving loading command issued by the computing resource controller 8130, and configure the target computing resource 8120 of the target container 8110 based on the target virtual partition specified by the computing resource controller 8130 to be loaded. The data system is a distributed container system, which uses containerization technology, resource management strategy and virtualization technology to manage and schedule computing resources to ensure that data processing tasks are efficiently and securely executed in the target container, for example, a Hadoop distributed system. The target server is a server that deploys multiple containers, and the target server runs the target container, the target computing resource (such as a container cloud disk) and the computing resource controller (such as an NVMe controller), for example, a bare metal server (Bare Metal Server), which is a physical server that does not install any virtualization software and directly runs an operating system and an application. The container resource management unit is a system component for implementing resource allocation, monitoring and adjustment at the target server level, which closely cooperates with the computing resource controller to ensure that the target container can safely and efficiently use the computing resource according to the preset strategy. For example, the TDCo computing resource controller is a hardware or software component located inside the target server and responsible for directly managing specific computing resources. It works with the container resource management unit to ensure that the target container can safely and efficiently access and use the target computing resource configured for it.In the embodiment, the computing resource controller undertakes the tasks of identifying the target virtual partition corresponding to the target container, determining the target namespace bound thereto, loading the resource configuration file, and delivering the resource configuration to the container resource management unit, etc. For example, the NVMe controller. In an optional embodiment of the present specification, the system 800 further comprises a management platform 820; the management platform 820 is configured to send a namespace addition request to the container resource management unit 8140, wherein the namespace addition request comprises the configuration parameter of the target computing resource 8120; and the container resource management unit 8140 is further configured to receive the namespace addition request, generate a resource configuration file of the target computing resource 8120 based on the configuration parameter, and allocate a corresponding target namespace to the resource configuration file from a plurality of pre-divided namespaces, wherein the namespace is an address space logically divided for the computing resource. The management platform is a software system for global resource scheduling, policy making, permission control, and providing a unified management interface, for example, EBS and ECS. EBS (Elastic Block Store) is a block storage service that provides functions such as cloud disk creation, mounting, backup, etc., and ECS (Elastic Container Service) is a container orchestration service that is used to manage the life cycle, deployment, scaling, etc. of containers. In an optional embodiment of the present specification, the management platform 820 is further configured to allocate a corresponding target virtual partition to the target namespace from a plurality of pre-created virtual partitions, and bind the target namespace and the target virtual partition, wherein the virtual partition is a virtual device having a configuration permission of the computing resource. In an optional embodiment of the present specification, the computing resource controller 8130 is further configured to obtain target verification information sent by a container engine of a user container, verify whether the target container 8110 has access permission for the target computing resource 8120 based on the target verification information and pre-generated initial verification information, and determine that the user container is the target container 8110 in the case where the verification is passed. In the present disclosure, the computing resource controller is configured to determine a target virtual partition corresponding to a target computing resource of a target container; query a target namespace having a binding relationship with the target virtual partition based on the target virtual partition; obtain a resource configuration file corresponding to the target namespace, load the target virtual partition, and deliver the resource configuration file to a container resource management unit through the target virtual partition; and the container resource management unit is configured to receive the resource configuration file delivered by the computing resource controller, and configure the target computing resource of the target container based on the resource configuration file.The binding of the namespace and the computing resource is realized through the namespace and the virtual partition with the binding relationship, and the computing resource configuration is completed on the basis, the security isolation of the computing resource of the container is ensured, the illegal access is effectively prevented, the direct and efficient access of the target container to the configured target computing resource is ensured, the isolation and the access performance of the container resource are improved, and the stability and the system performance of the data system are improved. The above is a schematic scheme of the data system of the embodiment. It should be noted that the technical scheme of the data system and the technical schemes of the container resource configuration method and the computing resource access processing method belong to the same concept, and the details of the technical scheme of the data system which are not described in detail can be referred to the description of the technical scheme of the container resource configuration method or the computing resource access processing method. FIG. 9 shows a structural block diagram of a computing device provided by an embodiment of the present specification. The components of the computing device 900 include but are not limited to a memory 910 and a processor 920. The processor 920 is connected with the memory 910 through a bus 930, and a database 950 is used to save data. The computing device 900 further includes an access device 940, which enables the computing device 900 to communicate via one or more networks 960. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 940 can include one or more of any type of network interface (for example, a network interface card (NIC)), such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a worldwide interoperability for microwave access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC), or the like.In an embodiment of the present specification, the above-mentioned components of the computing device 900 and other components not shown in FIG. 9 can also be connected to each other, for example, through a bus. It should be understood that the computing device structure block diagram shown in FIG. 9 is only for the purpose of example, and is not a limitation on the scope of the present specification. Those skilled in the art can add or replace other components as needed. The computing device 900 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (for example, a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (for example, a smartphone), a wearable computing device (for example, a smart watch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). The computing device 900 can also be a mobile or stationary server. Among them, the processor 920 is used to execute the computer program / instructions which realize the steps of the above-mentioned container resource configuration method or the access processing method of the computing resource when executed by the processor. The above is a schematic scheme of a computing device according to an embodiment of the present specification. It should be noted that the technical scheme of the computing device belongs to the same concept as the technical schemes of the container resource configuration method and the access processing method of the computing resource, and the details of the technical scheme of the computing device that are not described in detail can be referred to the description of the technical scheme of the container resource configuration method or the access processing method of the computing resource. An embodiment of the present specification also provides a computer readable storage medium which stores computer programs / instructions, which realize the steps of the above-mentioned container resource configuration method or the access processing method of the computing resource when executed by the processor. The above is a schematic scheme of a computer readable storage medium according to an embodiment of the present specification. It should be noted that the technical scheme of the storage medium belongs to the same concept as the technical schemes of the container resource configuration method and the access processing method of the computing resource, and the details of the technical scheme of the storage medium that are not described in detail can be referred to the description of the technical scheme of the container resource configuration method or the access processing method of the computing resource. An embodiment of the present specification also provides a computer program product including computer programs / instructions, which realize the steps of the above-mentioned container resource configuration method or the access processing method of the computing resource when executed by the processor. The above is a schematic scheme of a computer program product according to an embodiment of the present specification.It should be noted that the technical solution of the computer program product belongs to the same concept as the technical solutions of the container resource configuration method and the computing resource access processing method described above. The technical solution of the computer program product is not described in detail. The details can be referred to the description of the technical solution of the container resource configuration method or the computing resource access processing method. The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different than the order in which they are recited in the embodiments and still achieve desirable results. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous. The computer instructions include computer program code, which can be in the form of source code, object code, executable code, or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content contained in the computer readable medium can be appropriately added or reduced according to the requirements of patent practice. For example, according to the patent practice in some regions, the computer readable medium does not include electrical carrier signals and telecommunication signals. It should be noted that for the foregoing method embodiments, in order to facilitate description, they are all expressed as a combination of a series of actions, but those skilled in the art should know that the present disclosure is not limited by the order of the actions described, because according to the present disclosure, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily necessary for the present disclosure. In the above embodiments, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. The preferred embodiments of the above disclosure are used to help explain the present specification. The alternative embodiments do not describe all the details and limit the invention to the described specific embodiments. Obviously, many modifications and changes can be made according to the content of the present disclosure.The embodiments are chosen and described in order to best explain the principles of the disclosure and its practical application to thereby enable others skilled in the art to best utilize the disclosure. The present disclosure is only limited by the scope of the claims and the equivalent thereof.

Claims

CLAIM 1. A method of configuring container resources, comprising: determining a target virtual partition corresponding to a target computing resource of a target container; querying a target namespace having a binding relationship with the target virtual partition based on the target virtual partition; obtaining a resource configuration file corresponding to the target namespace; loading the target virtual partition, and configuring the target computing resource of the target container based on the resource configuration file.

2. The method of claim 1, before the obtaining the resource configuration file corresponding to the target namespace, further comprising: obtaining a configuration parameter of the target computing resource, and generating a resource configuration file of the target computing resource based on the configuration parameter.

3. The method of claim 2, after the generating the resource configuration file of the target computing resource based on the configuration parameters, further comprising: allocating a corresponding target namespace for the resource configuration file from a plurality of pre-divided namespaces, wherein the namespaces are address spaces logically divided for computing resources.

4. The method of claim 3, after assigning the corresponding target namespace to the resource configuration file from the plurality of pre-divided namespaces, further comprising: allocating a corresponding target virtual partition for the target namespace from a plurality of pre-created virtual partitions, and binding the target namespace and the target virtual partition, wherein the virtual partitions are virtual devices having configuration permissions for computing resources.

5. The method of any of claims 1-4, after the loading the target virtual partition, the configuring the target computing resource of the target container based on the resource configuration file, further comprising: starting the target container based on the target computing resource.

6. The method of claim 5, before the starting the target container based on the target compute resource, further comprising: obtaining target verification information sent by a container engine of a user container; verifying whether the target container has access permissions for the target computing resource based on the target verification information and pre-generated initial verification information; in a case where the verification passes, determining that the user container is the target container.

7. The method of claim 6, after the checking whether the target container has the access right to the target computing resource based on the target checking information and the pre-generated initial checking information, further comprising: in a case where the verification fails, prohibiting starting of the target container.

8. The method of claim 6 or 7, before the verifying whether the target container has the access permissions for the target computing resource based on the target verification information and the pre-generated initial verification information, further comprising: obtaining a mounting relationship between the target container and the target computing resource; based on the mounting relationship between the target container and the target computing resource, identifying whether there is a permission to generate the initial verification information of the target container; if yes, generating the initial verification information of the target container.

9. A method of access processing of a computing resource, comprising: receiving an access request for a target computing resource sent by a container engine of a user container, wherein the access request includes target verification information; verifying whether the user container has access permissions for the target computing resource based on the target verification information and pre-generated initial verification information, wherein the target computing resource is configured by the method of claims 1-9; in a case where the verification passes, determining that the user container is the target container; starting the target container based on the target computing resource, and allowing the target container to access the target computing resource.

10. The method of claim 9, after said verifying whether the user container has access to the target computing resource based on the target verification information and the pre-generated initial verification information, further comprising: in a case where the verification fails, intercepting the access request.

11. The method of claim 9 or 10, before the verifying whether the target container has the access right to the target computing resource based on the target verification information and the pre-generated initial verification information, further comprising: obtaining a mounting relationship between the target container and the target computing resource; identifying whether there is a right to generate the initial verification information of the target container based on the mounting relationship between the target container and the target computing resource; and if not, intercepting the access request.

12. A data system, the system comprising a target server, the target server including a target container, a target computing resource, a computing resource controller, and a container resource management unit; the computing resource controller being configured to determine a target virtual partition corresponding to the target computing resource of the target container, query a target namespace having a binding relationship with the target virtual partition based on the target virtual partition, and drive loading the target virtual partition; and the container resource management unit being configured to receive a drive loading command issued by the computing resource controller, and configure the target computing resource of the target container based on the target virtual partition specified by the computing resource controller to be loaded.

13. The system according to claim 12, further comprising a management and control platform; the management and control platform being configured to send a namespace attachment request to the container resource management and control unit, wherein, The space additional request comprises a configuration parameter of the target computing resource; and the container resource management unit is further configured to receive the namespace additional request, generate a resource configuration file of the target computing resource based on the configuration parameter, and assign a corresponding target namespace to the resource configuration file from a plurality of pre-divided namespaces, wherein the namespace is an address space logically divided by the computing resource. The virtual partition is a virtual device having a configuration right of the computing resource.

14. The system of claim 13, wherein the management and control platform is further configured to: allocate a target virtual partition corresponding to the target namespace from a plurality of pre-created virtual partitions, and bind the target namespace and the target virtual partition, wherein the target virtual partition is configured to: provide a target virtual network for the target namespace, and provide a target virtual storage for the target namespace.

15. The system of any one of claims 12-14, the computing resource controller is further configured to obtain target verification information sent by a container engine of a user container, verify whether the target container has the access right to the target computing resource based on the target verification information and pre-generated initial verification information, and determine that the user container is the target container if the verification is passed. a memory and a processor; 16. A computing device comprising: the memory is configured to store computer programs / instructions, and the processor is configured to execute the computer programs / instructions, which realize the steps of the method of any one of claims 1-11 when executed by the processor.

17. A computer readable storage medium, which stores computer programs / instructions, which realize the steps of the method of any one of claims 1-11 when executed by a processor.

18. A computer program product, comprising computer programs / instructions, which realize the steps of the method of any one of claims 1-11 when executed by a processor. ​

Citation Information

Patent Citations

  • Memory sub-system with multiple ports having single root virtualization

    CN113396399A

  • Access request processing method, container cloud platform, electronic equipment and storage medium

    CN113672901A

  • Network configuration method and device of Kubernetes cluster, and electronic equipment

    CN115150268A

Cited By

  • Cache management method, reasoning method, cache management unit, reasoning unit, electronic equipment and storage medium

    CN121349911A