CN110175077A - A kind of method and system based on order management container resource - Google Patents

A kind of method and system based on order management container resource Download PDF

Info

Publication number
CN110175077A
CN110175077A CN201910445869.XA CN201910445869A CN110175077A CN 110175077 A CN110175077 A CN 110175077A CN 201910445869 A CN201910445869 A CN 201910445869A CN 110175077 A CN110175077 A CN 110175077A
Authority
CN
China
Prior art keywords
container
resource
tenant
service
role
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201910445869.XA
Other languages
Chinese (zh)
Inventor
石光银
孙思清
高传集
蔡卫卫
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur Cloud Information Technology Co Ltd
Original Assignee
Inspur Cloud Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur Cloud Information Technology Co Ltd filed Critical Inspur Cloud Information Technology Co Ltd
Priority to CN201910445869.XA priority Critical patent/CN110175077A/en
Publication of CN110175077A publication Critical patent/CN110175077A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/46Multiprogramming arrangements
    • G06F9/50Allocation of resources, e.g. of the central processing unit [CPU]
    • G06F9/5005Allocation of resources, e.g. of the central processing unit [CPU] to service a request
    • G06F9/5027Allocation of resources, e.g. of the central processing unit [CPU] to service a request the resource being a machine, e.g. CPUs, Servers, Terminals
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/45583Memory management, e.g. access or allocation

Abstract

The invention discloses a kind of method and system based on order management container resource, belong to the applied technical field of container.Method based on order management container resource of the invention, tenant is in newly-built container, the container cluster role of initialization container service tenant's administrator role, is defined access resource and movement, and tenant is tied on container cluster role in container service;After container service receives access request, application interface services device goes unification authentication platform to be authenticated, and after certification passes through, is authenticated using the user role binding of container to access resource, returns to operating resource information after the authentication is passed;Tenant accesses the application interface services device of specific container service.The method based on order management container resource of the invention not only can guarantee the safety of tide cloud container service, but also user can be allowed using direct process container Service Source is ordered, and have good application value.

Description

A kind of method and system based on order management container resource
Technical field
The present invention relates to the applied technical fields of container, specifically provide a kind of method based on order management container resource and System.
Background technique
Container technique is the PaaS technology of popular offer micro services, and Kubernetes is recent most popular appearance Device layout administrative skill, Kubernetes are the completely new leading schemes of the distributed structure/architecture based on container technique, On the basis of Docker technology, deployment operation, scheduling of resource, service discovery and dynamic retractility etc. one is provided for the application of containerization Series function improves the convenience and high availability of extensive container cluster management.
Each internet manufacturer has launched the public cloud container service based on Kubernetes, how direct by order Process container Service Source is the problem that each cloud manufacturer needs to solve.
Tide cloud is based on Kubernetes and provides container service, and user can buy container service by tide cloud, can To go management container service resource by tide cloud console.But due to tide cloud trustship container service, cause user cannot Directly log in container service node, this just need to provide the user with it is a kind of can direct process container Service Source method, allow User can also manage the resource of oneself container service under the premise of without logging into container service node.
Summary of the invention
Technical assignment of the invention is in view of the above problems, to provide one kind and allow user without logging into container service section Under the premise of point, the resource of container service can be directly managed by ordering, not only can guarantee the safety of tide cloud container service, but also User can be allowed to use the method based on order management container resource for ordering direct process container Service Source.
The further technical assignment of the present invention is to provide a kind of system based on order management container resource.
To achieve the above object, the present invention provides the following technical scheme that
A method of based on order management container resource, tenant initializes in container service and holds in newly-built container Device services the container cluster role of tenant's administrator role, is defined to access resource and movement, and tenant is tied to appearance On device cluster role;After container service receives access request, application interface services device goes unification authentication platform to be authenticated, certification By rear, access resource is authenticated using the user role binding of container, returns to operating resource information after the authentication is passed;It rents Family accesses the application interface services device of specific container service.
The method based on order management container resource allows user under the premise of without logging into container service node, Ke Yitong Cross the resource of order directly management container service.Not only it ensure that the safety of tide cloud container service, but also can allow user that can make With the direct process container Service Source of order.
Preferably, tenant calls container service interface module by container service interface assembly process container resource, visit Ask the application interface services device of specific container service.
Preferably, container layout component profile can be generated in tenant, in machine where container layout order line component Device executes container layout component profile script, connects container service.
Preferably, the container layout component profile supports Intranet access and extranet access.
Preferably, tenant, when creating container service cluster, initialization container services tenant's administrator role to container In Service Instance.
Preferably, calling the application interface services device of container service, application interface when tenant accesses container service interface After server receives request, unification authentication platform is called to authenticate user identifier, after certification passes through, container role can be called It is authenticated, after authentication all passes through, the resource information for returning to tenant request gives container service interface.
Preferably, need first to log in container service interface when tenant is want through command-line access container service cluster, under Carry container layout component profile.
Preferably, tenant is initialised to container layout component profile in container layout order line component, tenant Use the application interface services device of container layout order line component call container service;After interface server receives request, call Unification authentication platform authenticates user identifier, after certification passes through, container role is called to authenticate;When authentication is all logical Later, the resource information for returning to tenant request gives container layout order line component, and is output in order line.
A kind of system based on order management container resource, container service carry out unified certification using unification authentication platform, User authentication, subscription authentication, user role binding and access role, control is defined in the application interface services device of container service to visit Ask access authorization for resource, tenant's interface assembly passes through cluster management or container layout component profile process container resource.
The method based on order management container resource is realized by the system based on order management container resource.Based on life The method for enabling management container resource, for tenant in newly-built container, initialization container services tenant administrator angle in container service The container cluster role of color is defined access resource and movement, and tenant is tied on container cluster role;Container clothes After business receives access request, application interface services device goes unification authentication platform to be authenticated, and after certification passes through, uses the use of container Family role bindings authenticate access resource, return to operating resource information after the authentication is passed;Tenant accesses specific container clothes The application interface services device of business.
Tenant calls container service interface module by container service interface assembly process container resource, accesses specific hold The application interface services device of device service.Tenant can also generate container layout component profile, in container layout order line group Machine executes container layout component profile script where part, connects container service.
Preferably, the container layout component profile supports Intranet access and extranet access.
Compared with prior art, the method for the invention based on order management container resource has beneficial effect following prominent Fruit: providing a method based on order management container service resource, allow user under the premise of without logging into container service node, The resource of container service can be directly managed by ordering.Not only it ensure that the safety of tide cloud container service, but also can allow user The direct process container Service Source of order can be used.User is improved to the operability of oneself container service, is promoted to oneself The managerial ability of service application.With good application value.
Detailed description of the invention
Fig. 1 is the flow chart of the method for the present invention based on order management container resource;
Fig. 2 is the operational flowchart of the method for the present invention based on order management container resource;
Fig. 3 is the architecture diagram of the system of the present invention based on order management container resource.
Specific embodiment
Below in conjunction with drawings and examples, to the method and system of the invention based on order management container resource make into One step is described in detail.
Embodiment
Wherein, Kubernetes: container layout component.Portal: interface assembly.Kubeconfig: container layout component Configuration file.Apiserver: application interface services device.Cks-web: container service interface assembly.Cks-core-api: container Service interface component.Trident-admin: container service tenant's administrator role.Clusterrole: container cluster role. Kubectl: container layout order line component.
As shown in Figure 1, the method for the invention based on order management container resource, tenant is in newly-built container, in container The container cluster role of initialization container service tenant's administrator role, is defined access resource and movement in service, and Tenant is tied on container cluster role;After container service receives access request, application interface services device goes unified certification flat Platform is authenticated, and after certification passes through, is authenticated using the user role binding of container to access resource, is returned after the authentication is passed Operating resource information;Tenant accesses the application interface services device of specific container service.The quantity of container service can be according to need The difference wanted and it is different.It include container service 1 and container service 2 in the present invention.
Tenant calls container service interface module by container service interface assembly process container resource, accesses specific hold The application interface services device of device service.Tenant can also generate container layout component profile, in container layout order line group Machine executes container layout component profile script where part, connects container service.Container layout component profile is supported Intranet access and extranet access.
It is illustrated in figure 2 tide container service operational flowchart:
For tenant when creating container service cluster, initialization container services tenant's administrator role to container service example In.
When tenant accesses container service interface, the application interface services device of container service is called, application interface services device is received To after request, unification authentication platform is called to authenticate user identifier, after certification passes through, container role can be called to reflect Power, after authentication all passes through, the resource information for returning to tenant request gives container service interface.
When tenant is want through command-line access container service cluster, need first to log in container service interface, downloading container is compiled Arrange component profile.
Tenant is initialised to container layout component profile in container layout order line component, and tenant is compiled using container Arrange the application interface services device of order line component call container service;After interface server receives request, call unified certification flat Platform authenticates user identifier, after certification passes through, container role is called to authenticate;After authentication all passes through, return The resource information of tenant request gives container layout order line component, and is output in order line.
Tide container service command operation sample:
Kubectl config set-cluster ice-cluster--server=https: // 117.73.8.195: 6443--insecure-skip-tls-verify=true
Kubectl config set-context inspurtest14-ice-cluster--cluster=ice- cluster
Kubectl config set-credentials inspurtest14--token=tenant token
Kubectl config set-context inspurtest14-ice-cluster--user= inspurtest14
kubectl config use-context inspurtest14-ice-cluster
kubectl get node
As shown in figure 3, the system of the invention based on order management container resource, container service uses unification authentication platform Unified certification is carried out, user authentication, subscription authentication, user role binding are defined in the application interface services device of container service and is visited Ask role, control access access authorization for resource, tenant's interface assembly is held by cluster management or the operation of container layout component profile Device resource.
Wherein, tenant is in newly-built container, the container of initialization container service tenant's administrator role in container service Cluster role is defined access resource and movement, and tenant is tied on container cluster role;Container service receives visit After asking request, application interface services device goes unification authentication platform to be authenticated, and after certification passes through, is tied up using the user role of container It is fixed that access resource is authenticated, operating resource information is returned after the authentication is passed;Tenant accesses the application of specific container service Interface server.
In the system kind based on order management container resource, container service carries out unification using tide unification authentication platform Certification.The access role of user is defined, control access access authorization for resource binds tenant, tenant is allowed to operate User Defined Resource.Tenant By container layout component profile in inside and outside or outer net process container resource.
Tenant calls container service interface module by container service interface assembly process container resource, accesses specific hold The application interface services device of device service.Tenant can also generate container layout component profile, in container layout order line group Machine executes container layout component profile script where part, connects container service.
Container layout component profile supports Intranet access and extranet access.
Embodiment described above, the only present invention more preferably specific embodiment, those skilled in the art is at this The usual variations and alternatives carried out within the scope of inventive technique scheme should be all included within the scope of the present invention.

Claims (10)

1. a kind of method based on order management container resource, it is characterised in that: tenant is in newly-built container, in container service Initialization container services the container cluster role of tenant's administrator role, is defined to access resource and movement, and tenant It is tied on container cluster role;After container service receives access request, application interface services device goes unification authentication platform to carry out Certification after certification passes through, authenticates access resource using the user role binding of container, operation money is returned after the authentication is passed Source information;Tenant accesses the application interface services device of specific container service.
2. the method according to claim 1 based on order management container resource, it is characterised in that: tenant is taken by container Business interface assembly process container resource, calls container service interface module, accesses the application interface services device of specific container service.
3. the method according to claim 2 based on order management container resource, it is characterised in that: appearance can be generated in tenant Device layout component profile executes container layout component profile script in machine where container layout order line component, Connect container service.
4. the method according to claim 3 based on order management container resource, it is characterised in that: the container layout group Part configuration file supports Intranet access and extranet access.
5. the method according to claim 4 based on order management container resource, it is characterised in that: tenant is in creation container When service cluster, initialization container services tenant's administrator role into container service example.
6. the method according to claim 5 based on order management container resource, it is characterised in that: tenant accesses container clothes When business interface, the application interface services device of container service is called, after application interface services device receives request, calls unified certification flat Platform authenticates user identifier, after certification passes through, container role can be called to authenticate, after authentication all passes through, returned The resource information for returning tenant request gives container service interface.
7. the method according to claim 6 based on order management container resource, it is characterised in that: tenant wants to pass through order When row access container service cluster, needs first to log in container service interface, download container layout component profile.
8. the method according to claim 7 based on order management container resource, it is characterised in that: tenant is container layout Component profile is initialised in container layout order line component, and tenant is taken using container layout order line component call container The application interface services device of business;After interface server receives request, calls unification authentication platform to authenticate user identifier, recognize After card passes through, container role is called to authenticate;After authentication all passes through, the resource information of tenant request is returned to container Layout order line component, and be output in order line.
9. a kind of system based on order management container resource, it is characterised in that: in the system, container service uses unified certification Platform carries out unified certification, and user authentication, subscription authentication, user role binding are defined in the application interface services device of container service And access role, control access access authorization for resource, tenant's interface assembly are grasped by cluster management or container layout component profile Make container resource.
10. the system according to claim 9 based on order management container resource, it is characterised in that: the container layout Component profile supports Intranet access and extranet access.
CN201910445869.XA 2019-05-27 2019-05-27 A kind of method and system based on order management container resource Pending CN110175077A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910445869.XA CN110175077A (en) 2019-05-27 2019-05-27 A kind of method and system based on order management container resource

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910445869.XA CN110175077A (en) 2019-05-27 2019-05-27 A kind of method and system based on order management container resource

Publications (1)

Publication Number Publication Date
CN110175077A true CN110175077A (en) 2019-08-27

Family

ID=67695954

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910445869.XA Pending CN110175077A (en) 2019-05-27 2019-05-27 A kind of method and system based on order management container resource

Country Status (1)

Country Link
CN (1) CN110175077A (en)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110515602A (en) * 2019-09-17 2019-11-29 成都源动数据科技有限公司 A kind of online interaction formula programming opening experiment system
CN110704165A (en) * 2019-10-08 2020-01-17 浪潮云信息技术有限公司 High-availability deployment method for container
CN111813582A (en) * 2020-07-28 2020-10-23 东北大学 Ice service deployment and arrangement method
CN112468463A (en) * 2020-11-13 2021-03-09 福建福诺移动通信技术有限公司 Device and method for arranging scene capacity based on cloud native capacity gateway
CN113132295A (en) * 2019-12-30 2021-07-16 北京懿医云科技有限公司 Method and device for accessing extranet by cluster intranet, storage medium and electronic equipment
CN113364727A (en) * 2020-03-05 2021-09-07 北京金山云网络技术有限公司 Container cluster system, container console and server
WO2022247359A1 (en) * 2021-05-27 2022-12-01 北京百度网讯科技有限公司 Cluster access method and apparatus, electronic device, and medium
US11947660B2 (en) 2021-08-31 2024-04-02 International Business Machines Corporation Securing pods in a container orchestration environment

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130145006A1 (en) * 2011-12-06 2013-06-06 Sap Portals Israel Ltd Multi-tenant infrastructure
CN105045656A (en) * 2015-06-30 2015-11-11 深圳清华大学研究院 Virtual container based big data storage and management method
CN107438067A (en) * 2017-06-27 2017-12-05 北京溢思得瑞智能科技研究院有限公司 A kind of multi-tenant construction method and system based on mesos container cloud platforms
CN107948203A (en) * 2017-12-29 2018-04-20 平安科技(深圳)有限公司 A kind of container login method, application server, system and storage medium
CN108989091A (en) * 2018-06-22 2018-12-11 杭州才云科技有限公司 Based on the tenant network partition method of Kubernetes network, storage medium, electronic equipment
CN109032758A (en) * 2018-07-31 2018-12-18 曙光信息产业(北京)有限公司 Container swarm intelligence life cycle management method and device
CN109413065A (en) * 2018-10-25 2019-03-01 山东浪潮云信息技术有限公司 A kind of cluster safety management method based on container
CN109474632A (en) * 2018-12-28 2019-03-15 优刻得科技股份有限公司 User is authenticated and the method, apparatus of rights management, system and medium
CN109800056A (en) * 2019-01-16 2019-05-24 杭州趣链科技有限公司 A kind of block chain dispositions method based on container

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130145006A1 (en) * 2011-12-06 2013-06-06 Sap Portals Israel Ltd Multi-tenant infrastructure
CN105045656A (en) * 2015-06-30 2015-11-11 深圳清华大学研究院 Virtual container based big data storage and management method
CN107438067A (en) * 2017-06-27 2017-12-05 北京溢思得瑞智能科技研究院有限公司 A kind of multi-tenant construction method and system based on mesos container cloud platforms
CN107948203A (en) * 2017-12-29 2018-04-20 平安科技(深圳)有限公司 A kind of container login method, application server, system and storage medium
CN108989091A (en) * 2018-06-22 2018-12-11 杭州才云科技有限公司 Based on the tenant network partition method of Kubernetes network, storage medium, electronic equipment
CN109032758A (en) * 2018-07-31 2018-12-18 曙光信息产业(北京)有限公司 Container swarm intelligence life cycle management method and device
CN109413065A (en) * 2018-10-25 2019-03-01 山东浪潮云信息技术有限公司 A kind of cluster safety management method based on container
CN109474632A (en) * 2018-12-28 2019-03-15 优刻得科技股份有限公司 User is authenticated and the method, apparatus of rights management, system and medium
CN109800056A (en) * 2019-01-16 2019-05-24 杭州趣链科技有限公司 A kind of block chain dispositions method based on container

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
徐飞: "基于Kubernetes的多租户网络隔离的设计与实现", 《中国优秀硕士学位论文全文数据库 信息科技辑》 *

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110515602A (en) * 2019-09-17 2019-11-29 成都源动数据科技有限公司 A kind of online interaction formula programming opening experiment system
CN110704165A (en) * 2019-10-08 2020-01-17 浪潮云信息技术有限公司 High-availability deployment method for container
CN113132295A (en) * 2019-12-30 2021-07-16 北京懿医云科技有限公司 Method and device for accessing extranet by cluster intranet, storage medium and electronic equipment
CN113132295B (en) * 2019-12-30 2023-04-28 北京懿医云科技有限公司 Method and device for accessing extranet through intranet of cluster, storage medium and electronic equipment
CN113364727A (en) * 2020-03-05 2021-09-07 北京金山云网络技术有限公司 Container cluster system, container console and server
CN113364727B (en) * 2020-03-05 2023-04-18 北京金山云网络技术有限公司 Container cluster system, container console and server
CN111813582A (en) * 2020-07-28 2020-10-23 东北大学 Ice service deployment and arrangement method
CN111813582B (en) * 2020-07-28 2023-12-29 东北大学 Ice service deployment arrangement method
CN112468463A (en) * 2020-11-13 2021-03-09 福建福诺移动通信技术有限公司 Device and method for arranging scene capacity based on cloud native capacity gateway
CN112468463B (en) * 2020-11-13 2023-04-11 福建福诺移动通信技术有限公司 Device and method for arranging scene capacity based on cloud native capacity gateway
WO2022247359A1 (en) * 2021-05-27 2022-12-01 北京百度网讯科技有限公司 Cluster access method and apparatus, electronic device, and medium
US11947660B2 (en) 2021-08-31 2024-04-02 International Business Machines Corporation Securing pods in a container orchestration environment

Similar Documents

Publication Publication Date Title
CN110175077A (en) A kind of method and system based on order management container resource
US11175964B2 (en) Partner enablement services for managed service automation
US11734621B2 (en) Methods and systems for building custom appliances in a cloud-based network
US10705818B2 (en) Self-moving operating system installation in cloud-based network
US11442762B2 (en) Systems and methods for introspective application reporting to facilitate virtual machine movement between cloud hosts
US20190332511A1 (en) Tracking cloud installation information using cloud-aware kernel of operating system
US10986479B2 (en) Service management and provisioning for tenant service instances
Celesti et al. How to enhance cloud architectures to enable cross-federation
Nogales et al. Design and deployment of an open management and orchestration platform for multi-site nfv experimentation
US8924539B2 (en) Combinatorial optimization of multiple resources across a set of cloud-based networks
US8984505B2 (en) Providing access control to user-controlled resources in a cloud computing environment
US9930138B2 (en) Communicating with third party resources in cloud computing environment
US9202225B2 (en) Aggregate monitoring of utilization data for vendor products in cloud networks
KR101227267B1 (en) Cloud federation as a service
CN103001992B (en) Virtual desktop realizes system and its application method
US8977750B2 (en) Extending security platforms to cloud-based networks
US20120284405A1 (en) Systems and methods for management of virtual appliances in cloud-based network
US20110131306A1 (en) Systems and methods for service aggregation using graduated service levels in a cloud network
US20130346619A1 (en) Apparatus and methods for auto-discovery and migration of virtual cloud infrastructure
Cerrato et al. Toward dynamic virtualized network services in telecom operator networks
CN106375442A (en) Cross-platform device information management method and apparatus
Zhou et al. CloudsStorm: A framework for seamlessly programming and controlling virtual infrastructure functions during the DevOps lifecycle of cloud applications
CN112988572A (en) Multi-environment multi-channel multi-version simulation test method and device
CN105763545B (en) A kind of BYOD method and device
Volpato et al. OFQuality: a quality of service management module for software-defined networking

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20190827

RJ01 Rejection of invention patent application after publication