The invention discloses a container cloud safety protection method and
system constructed on basis of Kubernetes. The method comprises the steps of: adding a safety
protection system into a Kubernetescontainer cloud, and when clients access
microservices on the container cloud, by the
protection system, firstly carrying out first traffic cleaning of a transmission layer on a request; then forwarding to an
application layer protection system to carry out second traffic cleaning, and forwarding traffic after cleaning to the corresponding
microservices; and simultaneously collecting all access logs, then identifying abnormal access behaviors and
attack sources by intelligent analysis on the logs, generating a protection strategy, issuing the protection strategy to a protection subsystem, intercepting attacks and completing third traffic cleaning. The container cloud safety protection method and
system implement: 1, a deep protection
system of an
IP layer, the transmission layer and an
application layer; 2, intelligent generation and issuing of the protection strategy and linkage of the protection strategy with the protection system; and 3,
containerization of safety components and the advantages of rapid deployment, easiness for expansion, easiness for operation and maintenance and the like. The container cloud safety protection method and system are applicable to safety protection of the
microservices on the Kubernetes container cloud.