Computer system, container management method, and apparatus
View Patent ↗Computer systems, container management methods, and apparatuses are provided. In an implementation, a method comprises receiving a container creation request sent by a container cluster management node, wherein the container cluster management node is connected to the offloading card inserted in and communicably coupled to a computing node, obtaining a container image based on the container creation request, and indicating, through a communication channel established between the offloading card and the computing node, the computing node to create a container on the computing node based on the container image.
1 . A container management method, wherein the method comprises:
receiving, by an offloading card, a container creation request sent by a container cluster management node, wherein the container cluster management node is connected to the offloading card inserted in and communicably coupled to a computing node;
obtaining, by the offloading card, a container image based on the container creation request;
indicating, by the offloading card through a communication channel established between the offloading card and the computing node, the computing node to create a container on the computing node based on the container image;
obtaining, by the offloading card from a network service node through a network, a network resource;
setting, by the offloading card, a network processing rule for a virtual function device based on the network resource, wherein the network processing rule comprises a security group policy and an address mapping rule, wherein the security group policy comprises an access control list (ACL), wherein the address mapping rule comprises network address translation (NAT) and full NAT, and wherein the NAT comprises one or more of destination address translation (DNAT), source address translation (SNAT), or port translation (PNAT); and
setting, by the offloading card based on the network processing rule, the virtual function device in the container through the communication channel for the computing node to obtain the network resource using the virtual function device.
2 . The method according to claim 1 , wherein the indicating the computing node to create the container on the computing node based on the container image comprises:
creating, by the offloading card, a first virtual function device; associating, by the offloading card, the container image with the first virtual function device;
indicating, by the offloading card, the computing node to create a container operating environment for the container; and
mounting, by the offloading card, the first virtual function device under a root directory of the container.
3 . The method according to claim 2 , wherein the offloading card is further connected to a storage service node through a network, and the method further comprises:
applying, by the offloading card, to the storage service node for a storage resource;
setting, by the offloading card, a second virtual function device based on the storage resource; and
mounting the second virtual function device under a directory of the container through the communication channel.
4 . The method according to claim 3 , wherein the setting the second virtual function device based on the storage resource comprises:
creating, by the offloading card, the second virtual function device; and
associating, by the offloading card, the storage resource with the second virtual function device.
5 . The method according to claim 4 , wherein the mounting the second virtual function device under the directory of the container through the communication channel comprises:
connecting, by the offloading card, the second virtual function device to a secure container virtual machine for deploying the container, wherein the secure container virtual machine mounts the second virtual function device under the directory of the container in response to determining that the container is a secure container.
6 . The method according to claim 1 , wherein setting the network processing rule for the virtual function device based on the network resource comprises:
creating, by the offloading card, the virtual function device; and
associating, by the offloading card, the network resource with the virtual function device.
7 . The method according to claim 6 , wherein the network processing rule further comprises one or more of a load balancing policy, a routing rule, or quality of service.
8 . The method according to claim 1 , wherein the setting the virtual function device in the container through the communication channel comprises:
adding, by the offloading card, the virtual function device to a namespace of the container.
9 . The method according to claim 1 , wherein the setting the virtual function device in the container through the communication channel comprises:
connecting, by the offloading card, the virtual function device to a secure container virtual machine for deploying the container in response to determining that the container is a secure container.
10 . An offloading card, wherein the offloading card is inserted into a computing node and communicably coupled to the computing node and a container cluster management node, and the offloading card comprises at least one processor and a memory storing instructions for execution by the at least one processor to:
receive a container creation request sent by the container cluster management node;
obtain a container image based on the container creation request;
indicate, through a communication channel established between the offloading card and the computing node, the computing node to create a container on the computing node based on the container image;
obtain, from a network service node through a network, a network resource;
set a network processing rule for a virtual function device based on the network resource, wherein the network processing rule comprises a security group policy and an address mapping rule, wherein the security group policy comprises an access control list (ACL), wherein the address mapping rule comprises network address translation (NAT) and full NAT, and wherein the NAT comprises one or more of destination address translation (DNAT), source address translation (SNAT), or port translation (PNAT); and
set, based on the network processing rule, the virtual function device in the container through the communication channel for the computing node to obtain the network resource using the virtual function device.
11 . The offloading card according to claim 10 , wherein indicate the computing node to create the container on the computing node based on the container image comprises:
creating a first virtual function device;
associating the container image with the first virtual function device;
indicating the computing node to create a container operating environment for the container; and
mounting the first virtual function device under a root directory of the container.
12 . The offloading card according to claim 10 , wherein the offloading card is further connected to a storage service node through network, and the instructions are for execution by the at least one processor to:
apply to the storage service node for a storage resource;
set a second virtual function device based on the storage resource; and
mount the second virtual function device under a directory of the container through the communication channel.
13 . The offloading card according to claim 12 , wherein set the second virtual function device based on the storage resource comprises:
creating the second virtual function device; and
associating the storage resource with the second virtual function device.
14 . The offloading card according to claim 12 , wherein mount the second virtual function device under the directory of the container through the communication channel comprises:
connecting the second virtual function device to a secure container virtual machine for deploying the container, wherein the secure container virtual machine mounts the second virtual function device under the directory of the container in response to determining that the container is a secure container.
15 . The offloading card according to claim 10 , wherein set the network processing rule for the virtual function device based on the network resource comprises:
creating the virtual function device; and
associating the network resource with the virtual function device.
16 . The offloading card according to claim 10 , wherein the network processing rule further comprises one or more of a load balancing policy, a routing rule, or quality of service.
17 . The offloading card according to claim 10 , wherein set the virtual function device in the container through the communication channel comprises:
adding the virtual function device to a namespace of the container.
18 . The offloading card according to claim 10 , wherein set the virtual function device in the container through the communication channel comprises:
connecting the virtual function device to a secure container virtual machine for deploying the container in response to determining that the container is a secure container.