CN117135069A - Rights control method and device for container cloud platform - Google Patents

Rights control method and device for container cloud platform Download PDF

Info

Publication number
CN117135069A
CN117135069A CN202311186419.6A CN202311186419A CN117135069A CN 117135069 A CN117135069 A CN 117135069A CN 202311186419 A CN202311186419 A CN 202311186419A CN 117135069 A CN117135069 A CN 117135069A
Authority
CN
China
Prior art keywords
user
role
authority information
container
cloud platform
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202311186419.6A
Other languages
Chinese (zh)
Inventor
毕京浩
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Construction Bank Corp
CCB Finetech Co Ltd
Original Assignee
China Construction Bank Corp
CCB Finetech Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Construction Bank Corp, CCB Finetech Co Ltd filed Critical China Construction Bank Corp
Priority to CN202311186419.6A priority Critical patent/CN117135069A/en
Publication of CN117135069A publication Critical patent/CN117135069A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/28Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)

Abstract

The invention discloses a right control method and device of a container cloud platform, wherein the method comprises the following steps: when a user logs in a container cloud platform, determining a first role of the user; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles; when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role; and according to the second role of the user, inquiring the user permission information table and determining the second permission information of the user, so that the effectiveness and convenience of the management and control container cloud platform and the container can be improved.

Description

Rights control method and device for container cloud platform
Technical Field
The invention relates to the technical field of container cloud, in particular to a method and a device for controlling authority of a container cloud platform.
Background
This section is intended to provide a background or context to the embodiments of the invention that are recited in the claims. The description herein is not admitted to be prior art by inclusion in this section.
Rights management is an important ring of operation and maintenance system, and reasonable and effective rights management can effectively reduce the occurrence of production operation and maintenance accidents, can meet the corresponding operation and maintenance requirements of operation and maintenance personnel, reduce misoperation of the operation and maintenance personnel and the like. In the existing data center operation and maintenance system, login rights and operation rights of operation and maintenance personnel are strictly controlled, and the controllability of related operations is ensured through operations such as authorization, secondary authorization, right raising and the like. The personnel corresponding to each role has corresponding authority management, and the authority can be improved to a higher level through the authority when the authority is insufficient.
The operation and maintenance times of the traditional virtual machines generally control the operation rights of login personnel through the fort machine, and can control users logged into specific virtual machines and the like so as to control the corresponding operation rights of the users. However, after the container cloud platform is used, the container cloud platform can conveniently have corresponding functional operation authorities through the authority system when logging in, but when logging in a certain container, the management and control effect of the virtual machine is difficult to achieve because only one user is started by the operation of the container. If the read-only user does not have the modification authority of the container cloud platform, but can delete files or kill processes and the like when logging in the container, so that the system is unstable; or if the read-only user is restricted from logging into the container, the problem is inconvenient to check.
In view of the above problems, no effective solution has been proposed at present.
Disclosure of Invention
The embodiment of the invention provides a right control method of a container cloud platform, which is used for improving the effectiveness and convenience of managing and controlling the container cloud platform and a container, and comprises the following steps:
when a user logs in a container cloud platform, determining a first role of the user; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role;
and according to the second role of the user, inquiring the user authority information table, and determining the second authority information of the user.
The embodiment of the invention also provides a right control device of the container cloud platform, which is used for improving the effectiveness and convenience of managing and controlling the container cloud platform and the container, and comprises the following components:
the first authority information determining module is used for determining a first role of a user when the user logs in the container cloud platform; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
the role inquiring and switching module is used for inquiring a user role switching table according to a first role of the user when the user enters the container, determining a second role of the user and switching the user from the first role to the second role, wherein the user role switching table records the corresponding relation between the first role and the second role;
and the second authority information determining module is used for inquiring the user authority information table according to the second role of the user and determining the second authority information of the user.
The embodiment of the invention also provides computer equipment, which comprises a memory, a processor and a computer program stored on the memory and capable of running on the processor, wherein the authority control method of the container cloud platform is realized when the processor executes the computer program.
The embodiment of the invention also provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program realizes the authority control method of the container cloud platform when being executed by a processor.
The embodiment of the invention also provides a computer program product, which comprises a computer program, and the computer program realizes the authority control method of the container cloud platform when being executed by a processor.
In the embodiment of the invention, when a user logs in a container cloud platform, a first role of the user is determined; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles; when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role; and according to the second role of the user, inquiring the user authority information table, and determining the second authority information of the user.
According to the invention, through switching to the corresponding user when logging in according to the corresponding relationship between the container cloud platform and the user in the container, the linkage management of the user authority system in the container cloud platform and the container can be realized, the authority management and control of the existing operation and maintenance management are met, the basic requirement of operation and maintenance is met, the authority isolation and the authority control are effectively realized, and the effectiveness and the convenience of managing and controlling the container cloud platform and the container are improved.
Drawings
In order to more clearly illustrate the embodiments of the invention or the technical solutions in the prior art, the drawings that are required in the embodiments or the description of the prior art will be briefly described, it being obvious that the drawings in the following description are only some embodiments of the invention, and that other drawings may be obtained according to these drawings without inventive effort for a person skilled in the art. In the drawings:
FIG. 1 is a process flow diagram of a method for controlling rights of a container cloud platform in an embodiment of the invention;
FIG. 2 is a flowchart of a method for establishing a user rights information table in an embodiment of the present invention;
FIG. 3 is a flowchart of a method for establishing a user role switch table in an embodiment of the present invention;
fig. 4 is a schematic structural diagram of a rights control apparatus of a container cloud platform according to an embodiment of the present invention;
fig. 5 is a schematic diagram of a computer device according to an embodiment of the invention.
Detailed Description
For the purpose of making the objects, technical solutions and advantages of the embodiments of the present invention more apparent, the embodiments of the present invention will be described in further detail with reference to the accompanying drawings. The exemplary embodiments of the present invention and their descriptions herein are for the purpose of explaining the present invention, but are not to be construed as limiting the invention.
First, technical terms in the embodiment of the present invention will be described:
container cloud: container cloud is a product form emerging in cloud computing technology in recent two years, and is actually to divide resources according to containers, encapsulate the whole software runtime environment, and provide a platform for developers and system administrators to construct, publish and run distributed applications. When the container cloud is focused on resource sharing and isolation, container orchestration and deployment, it is closer to the concept of laas, and when the container cloud permeates into the application support and runtime environment, it is closer to Paas. In many enterprises, application release is a highly stressful, risky activity involving multiple teams. However, in a DevOps-capable organization, the risk of application release is low. Because iterative development is more convenient than traditional waterfall development models.
A container: a Container (Container) is a lighter, more flexible way of virtualizing, and it packages together everything that is needed by an application. The container includes all code, various dependencies and even an operating system, which allows applications to run almost anywhere. Therefore, the birth of the novel plastic cement solves an important problem: how to ensure proper operation of an application moving from one environment to another. It simply virtualizes the operating system and does not virtualize the underlying computer as a virtual machine.
Base mirror image: the Docker base image is the most basic and bottommost image in Docker. In Docker, the image is a software package that can be packaged and deployed, and the base image is the base of all other images. The Docker base image is used to build other images, which are themselves the most basic environments and collection of components, the smallest operating system image. The Docker base image includes a complete installer from the operating system to the various components on which various applications can be installed.
Application mirroring: the system mirror image and the application program are common application programs such as LAMP, LNMP, wordPress and pagoda panel Nodeis, namely, the application program is installed on the basis of the original system mirror image and is used for meeting the deployment requirements of certain applications such as websites, and the use threshold of a server is reduced.
System mirroring: pure versions of operating systems, such as Windows servers, centros 8.1, etc., which we commonly use, are system images.
Fig. 1 is a process flow diagram of a rights control method for a container cloud platform in an embodiment of the present invention. As shown in fig. 1, the authority control method of the container cloud platform in the embodiment of the present invention may include:
step 101, when a user logs in a container cloud platform, determining a first role of the user; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
102, when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role;
and step 103, inquiring a user authority information table according to the second role of the user, and determining second authority information of the user.
The following describes specific execution steps of the rights control method of the container cloud platform in the embodiment of the invention:
firstly, for step 101, when a user logs in a container cloud platform, a first role of the user can be determined; and then according to the first role of the user, inquiring a user authority information table to determine the first authority information of the user, wherein the authority information table records the authority information corresponding to the users with different roles. Specifically, the first authority information of the user characterizes the authority range that the user can execute when logging in the container cloud platform.
In one embodiment, the user roles may include at least one of the following roles: maintainers, developers or guests.
It should be noted that, depending on the existing rights management system of the container cloud platform, rights management may be classified into 3 levels, and users with different roles correspond to rights with different levels, for example, the roles of the users may include: maintainer (Maintainer), developer (Developer), and Guest (Guest). The management authority of all the deployment space resources under the system can be owned by the Maintainer authority, and mainly comprises the adding, deleting and checking authorities of various resources; the development permission can have management permission except deletion operation of all the deployment space resources under the system; the Guest rights can have read-only rights of all the deployment space resources under the system. In an embodiment, the user authority information table may also be established in advance.
Fig. 2 is a flowchart of a method for establishing a user right information table in an embodiment of the present invention. As shown in fig. 2, in one embodiment, the method may further include:
step 201, presetting authority information corresponding to users with different roles;
step 202, a user permission information table is established according to permission information corresponding to users with different roles.
In one embodiment, the method may further include: developers and visitors are added in the base image of the container in advance.
In one embodiment, the method may further include: and making an application image according to the basic image, and inheriting the user roles and the corresponding authority information of the basic image.
In one embodiment, the container cloud platform interfaces with a plurality of containers.
In the specific implementation, in order to realize the linkage management of the container cloud platform and the user authority system in the container, the basic mirror image can be modified. And adding development users and Guest users in the basic mirror image, and setting corresponding authorities for the two users respectively, wherein the Guest users are set as fewer operation authorities and are mainly used for viewing related logs and information.
The specific steps of transforming the base image and setting the operation authority can be as follows: according to the specification, the processes in the container are started and run by using non-root users, and remote login services such as sshd are not allowed to run, so that default entering the container is entered through an interface mode of kubectl exec, and after entering, the processes are started common users. The general user is a user running the program, defined as a development user, and designates gid (user identification) and uid (user group identification) of the development user; meanwhile, a Guest user can be added, and high-risk authorities such as rm (deleting a catalog or a file), su (switching user), sudo (allowing a system administrator to allow a common user to execute some or all root commands) and the like are strictly controlled; meanwhile, the development user can be set so as not to be closely changed to the Guest user; other rights of the development user and the Guest user are set by referring to the traditional virtual machine mode.
All container images are made based on the basic image or the derivative image of the basic image, and the user authority is loaded into the basic image by default in the mode, so that the developer is not allowed to modify, and the relevant files of the application can only be added according to the specifications.
After the first permission information of the user is determined according to the first role of the user, steps 102-103 may be executed, and when the user enters the container, a user role switching table is queried according to the first role of the user, a second role of the user is determined, and the user is switched from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role. And then, according to the second role of the user, inquiring the user authority information table to determine the second authority information of the user. In particular, the second rights information of the user characterizes the scope of rights that the user can execute when entering the interior of the container.
Fig. 3 is a flowchart of a method for establishing a user role switch table in an embodiment of the present invention. As shown in fig. 3, in one embodiment, the method may further include:
step 301, presetting a corresponding relation between a first role and a second role;
step 302, a user role switching table is established according to the corresponding relation between the first role and the second role.
In the implementation, as shown in table 1, when the user logged into the container cloud platform is the rights of the mainainer and the Developer, the corresponding user logged into the container is the Developer. When a user logging in the container cloud platform is a Guest right, the container cloud platform can be automatically switched to the Guest user when the kubecl exec interface is called. And the three authority levels of the container cloud platform can change the authority or actively apply for the authority to obtain the corresponding operation authority.
TABLE 1
Sequence number Container cloud platform rights User inside container
1 Maintainer Developer
2 Developer Developer
3 Guest Guest
As above, the management and control requirements of the existing operation and maintenance system can be met through the authority management of the container cloud platform and the linkage management of the authority in the container, and the existing operation and maintenance capability is effectively improved.
The embodiment of the invention also provides a right control device of the container cloud platform, which is described in the following embodiment. Because the principle of the device for solving the problem is similar to that of the authority control method of the container cloud platform, the implementation of the device can be referred to the implementation of the authority control method of the container cloud platform, and the repetition is omitted.
Fig. 4 is a schematic structural diagram of a rights control apparatus for a container cloud platform according to an embodiment of the present invention. As shown in fig. 4, the rights control apparatus for a container cloud platform in an embodiment of the present invention may specifically include:
a first authority information determining module 401, configured to determine a first role of a user when the user logs in the container cloud platform; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
the role query and switch module 402 is configured to query a user role switch table according to a first role of the user when the user enters the container, determine a second role of the user, and switch the user from the first role to the second role, where the user role switch table records a correspondence between the first role and the second role;
the second permission information determining module 403 is configured to query the user permission information table according to the second role of the user, and determine second permission information of the user.
In one embodiment, the user roles include at least one of the following roles:
maintainers, developers or guests.
In one embodiment, the method further comprises an adding module for:
developers and visitors are added in the base image of the container in advance.
In one embodiment, the method further comprises an application mirror creation module for:
and making an application image according to the basic image, and inheriting the user roles and the corresponding authority information of the basic image.
In one embodiment, the container cloud platform interfaces with a plurality of containers.
In one embodiment, the method further comprises a user authority information table establishing module for:
presetting authority information corresponding to users with different roles;
and establishing a user authority information table according to the authority information corresponding to the users with different roles.
In one embodiment, the method further comprises a user role switching table establishment module for:
presetting a corresponding relation between a first role and a second role;
and establishing a user role switching table according to the corresponding relation between the first role and the second role.
Based on the foregoing inventive concept, as shown in fig. 5, the present invention further proposes a computer device 500, including a memory 510, a processor 520, and a computer program 530 stored in the memory 510 and capable of running on the processor 520, where the processor 520 implements the rights control method of the container cloud platform when executing the computer program 530.
The embodiment of the invention also provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program realizes the authority control method of the container cloud platform when being executed by a processor.
The embodiment of the invention also provides a computer program product, which comprises a computer program, and the computer program realizes the authority control method of the container cloud platform when being executed by a processor.
In summary, in the embodiment of the present invention, when a user logs in the container cloud platform, a first role of the user is determined; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles; when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role; and according to the second role of the user, inquiring the user authority information table, and determining the second authority information of the user.
According to the invention, through switching to the corresponding user when logging in according to the corresponding relationship between the container cloud platform and the user in the container, the linkage management of the user authority system in the container cloud platform and the container can be realized, the authority management and control of the existing operation and maintenance management are met, the basic requirement of operation and maintenance is met, the authority isolation and the authority control are effectively realized, and the effectiveness and the convenience of managing and controlling the container cloud platform and the container are improved.
It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, and the like) having computer-usable program code embodied therein.
The present invention is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention. It will be understood that each flow and/or block of the flowchart illustrations and/or block diagrams, and combinations of flows and/or blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means which implement the function specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
The foregoing description of the embodiments has been provided for the purpose of illustrating the general principles of the invention, and is not meant to limit the scope of the invention, but to limit the invention to the particular embodiments, and any modifications, equivalents, improvements, etc. that fall within the spirit and principles of the invention are intended to be included within the scope of the invention.

Claims (17)

1. The authority control method of the container cloud platform is characterized by comprising the following steps of:
when a user logs in a container cloud platform, determining a first role of the user; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
when the user enters the container, inquiring a user role switching table according to a first role of the user, determining a second role of the user, and switching the user from the first role to the second role, wherein the user role switching table records a corresponding relation between the first role and the second role;
and according to the second role of the user, inquiring the user authority information table, and determining the second authority information of the user.
2. The method of claim 1, wherein the user roles include at least one of the following roles:
maintainers, developers or guests.
3. The method as recited in claim 2, further comprising:
developers and visitors are added in the base image of the container in advance.
4. A method as recited in claim 3, further comprising:
and making an application image according to the basic image, and inheriting the user roles and the corresponding authority information of the basic image.
5. The method of claim 1, wherein the container cloud platform interfaces with a plurality of containers.
6. The method as recited in claim 1, further comprising:
presetting authority information corresponding to users with different roles;
and establishing a user authority information table according to the authority information corresponding to the users with different roles.
7. The method as recited in claim 1, further comprising:
presetting a corresponding relation between a first role and a second role;
and establishing a user role switching table according to the corresponding relation between the first role and the second role.
8. A rights control apparatus for a container cloud platform, comprising:
the first authority information determining module is used for determining a first role of a user when the user logs in the container cloud platform; inquiring a user authority information table according to a first role of a user, and determining first authority information of the user, wherein the authority information table records authority information corresponding to users with different roles;
the role inquiring and switching module is used for inquiring a user role switching table according to a first role of the user when the user enters the container, determining a second role of the user and switching the user from the first role to the second role, wherein the user role switching table records the corresponding relation between the first role and the second role;
and the second authority information determining module is used for inquiring the user authority information table according to the second role of the user and determining the second authority information of the user.
9. The apparatus of claim 8, wherein the user roles comprise at least one of the following roles:
maintainers, developers or guests.
10. The apparatus of claim 9, further comprising an augmentation module to:
developers and visitors are added in the base image of the container in advance.
11. The apparatus of claim 10, further comprising an application mirroring fabrication module to:
and making an application image according to the basic image, and inheriting the user roles and the corresponding authority information of the basic image.
12. The apparatus of claim 8, wherein the container cloud platform interfaces with a plurality of containers.
13. The apparatus of claim 8, further comprising a user rights information table creation module for:
presetting authority information corresponding to users with different roles;
and establishing a user authority information table according to the authority information corresponding to the users with different roles.
14. The apparatus of claim 8, further comprising a user role switch table establishment module to:
presetting a corresponding relation between a first role and a second role;
and establishing a user role switching table according to the corresponding relation between the first role and the second role.
15. A computer device comprising a memory, a processor and a computer program stored on the memory and executable on the processor, characterized in that the processor implements the method of any of claims 1 to 7 when executing the computer program.
16. A computer readable storage medium, characterized in that the computer readable storage medium stores a computer program which, when executed by a processor, implements the method of any of claims 1 to 7.
17. A computer program product, characterized in that the computer program product comprises a computer program which, when executed by a processor, implements the method of any of claims 1 to 7.
CN202311186419.6A 2023-09-14 2023-09-14 Rights control method and device for container cloud platform Pending CN117135069A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202311186419.6A CN117135069A (en) 2023-09-14 2023-09-14 Rights control method and device for container cloud platform

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202311186419.6A CN117135069A (en) 2023-09-14 2023-09-14 Rights control method and device for container cloud platform

Publications (1)

Publication Number Publication Date
CN117135069A true CN117135069A (en) 2023-11-28

Family

ID=88856391

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202311186419.6A Pending CN117135069A (en) 2023-09-14 2023-09-14 Rights control method and device for container cloud platform

Country Status (1)

Country Link
CN (1) CN117135069A (en)

Similar Documents

Publication Publication Date Title
US10795733B2 (en) Server farm management
US11178207B2 (en) Software version control without affecting a deployed container
US11159392B2 (en) Managing service deployment
WO2019095936A1 (en) Method and system for building container mirror image, and server, apparatus and storage medium
US8869146B2 (en) Virtual machine migration
CN102262557B (en) Method for constructing virtual machine monitor by bus architecture and performance service framework
US20190347127A1 (en) Service provisioning and orchestration for virtual machine to container migration
US20150381435A1 (en) Migrating private infrastructure services to a cloud
US9106584B2 (en) Cloud infrastructure services
US11765034B2 (en) Enforcing policies in cloud domains with different application nomenclatures
US20050132367A1 (en) Method, apparatus and system for proxying, aggregating and optimizing virtual machine information for network-based management
US10721125B2 (en) Systems and methods for update propagation between nodes in a distributed system
US9170850B2 (en) Minimizing workload migrations during cloud maintenance operations
US10678775B2 (en) Determining integrity of database workload transactions
Bernstein Cloud foundry aims to become the OpenStack of PaaS
Mavridis et al. Orchestrated sandboxed containers, unikernels, and virtual machines for isolation‐enhanced multitenant workloads and serverless computing in cloud
US9710308B1 (en) Workflow for migration planning of data storage systems
US20150160955A1 (en) Dynamically modifiable component model
CN113296891B (en) Platform-based multi-scene knowledge graph processing method and device
CN113168406A (en) Isolated hierarchical runtime environment for multi-tenant databases
US11552959B2 (en) Access management system with a pre-commit verification engine
US10175976B1 (en) Systems and methods for avoiding version conflict in a shared cloud management tool
CN117135069A (en) Rights control method and device for container cloud platform
US20230421609A1 (en) Organization based access control with boundary access policies
Li et al. Research and Design of Docker Technology Based Authority Management System

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination