Security Policy Generation Using Container Metadata
US-2017279770-A1 · Sep 28, 2017 · US
US10270841B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-10270841-B1 |
| Application number | US-201615061260-A |
| Country | US |
| Kind code | B1 |
| Filing date | Mar 4, 2016 |
| Priority date | Mar 4, 2016 |
| Publication date | Apr 23, 2019 |
| Grant date | Apr 23, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
In one embodiment, a method includes receiving a trigger to deploy a particular container on cloud resources accessible thereto such that the cloud resources are provided by a plurality of cloud providers and such that the computer system and the plurality of cloud providers are configured to negotiate container deployment using an information exchange protocol. The information exchange protocol includes a preconfigured inquiry format and a preconfigured inquiry-response format. The method further includes generating a performance inquiry in relation to the particular container. In addition, the method includes transmitting the performance inquiry to the plurality of cloud providers. Moreover, the method includes receiving inquiry responses from at least some of the plurality of cloud providers. Additionally, the method includes causing the particular container to be deployed on resources of the particular cloud provider.
Opening claim text (preview).
What is claimed is: 1. A method comprising, by a computer system: receiving a trigger to deploy a particular container on cloud resources accessible to the computer system, wherein the cloud resources are provided by a plurality of cloud providers, wherein the computer system and the plurality of cloud providers are configured to negotiate container deployment using an information exchange protocol; wherein the information exchange protocol comprises a preconfigured inquiry format, a preconfigured inquiry-response format and a preconfigured scheduling format, the preconfigured inquiry format specifying an arrangement of inquiry fields, the preconfigured inquiry-response format specifying an arrangement of response fields, and the preconfigured scheduling format specifying an arrangement of scheduling fields; responsive to the trigger, generating a performance inquiry in relation to the particular container, wherein the performance inquiry comprises inquiry values corresponding to the arrangement of inquiry fields, wherein the inquiry values comprise an identifier of the particular container and an execution constraint; transmitting the performance inquiry to the plurality of cloud providers; receiving inquiry responses from at least some of the plurality of cloud providers, wherein the inquiry responses each comprise response values corresponding to the arrangement of response fields, the response values indicating capacity to execute the particular container in satisfaction of the execution constraint; and responsive to selection of a particular cloud provider, causing the particular container to be deployed on resources of the particular cloud provider, wherein the causing comprises: generating a scheduling message in relation to the particular container and the particular cloud provider, wherein the scheduling message comprises scheduling values corresponding to the arrangement of scheduling fields, and wherein the scheduling values comprise an instruction to execute the particular container; and transmitting the scheduling message to the particular cloud provider. 2. The method of claim 1 , wherein, for at least one of the inquiry responses, the response values comprise a performance metric related to a currently executing instance of the particular container. 3. The method of claim 2 , wherein the execution constraint indicates a region where the particular container is not permitted to execute. 4. The method of claim 1 , wherein the execution constraint is selected from the group consisting of a number of central processing units (CPUs), a constraint on a physical location where the particular container can be deployed and a required proximity to at least one other container. 5. The method of claim 1 , wherein the response values identify one or more time slots of available capacity for the particular container. 6. The method of claim 5 , wherein the response values comprise an articulation of available capacity for each of the one or more time slots. 7. The method of claim 1 , wherein the inquiry values and the response values are expressed in a markup language. 8. An information handling system comprising a processor, wherein the processor is operable to implement a method comprising: receiving a trigger to deploy a particular container on cloud resources accessible to the information handling system, wherein the cloud resources are provided by a plurality of cloud providers, wherein the information handling system and the plurality of cloud providers are configured to negotiate container deployment using an information exchange protocol; wherein the information exchange protocol comprises a preconfigured inquiry format, a preconfigured inquiry-response format and a preconfigured scheduling format, the preconfigured inquiry format specifying an arrangement of inquiry fields, the preconfigured inquiry-response format specifying an arrangement of response fields, and the preconfigured scheduling format specifying an arrangement of scheduling fields; responsive to the trigger, generating a performance inquiry in relation to the particular container, wherein the performance inquiry comprises inquiry values corresponding to the arrangement of inquiry fields, wherein the inquiry values comprise an identifier of the particular container and an execution constraint; transmitting the performance inquiry to the plurality of cloud providers; receiving inquiry responses from at least some of the plurality of cloud providers, wherein the inquiry responses each comprise response values corresponding to the arrangement of response fields, the response values indicating capacity to execute the particular container in satisfaction of the execution constraint; and responsive to selection of a particular cloud provider, causing the particular container to be deployed on resources of the particular cloud provider wherein the causing comprises: generating a scheduling message in relation to the particular container and the particular cloud provider, wherein the scheduling message comprises scheduling values corresponding to the arrangement of scheduling fields, and wherein the scheduling values comprise an instruction to execute the particular container; and transmitting the scheduling message to the particular cloud provider. 9. The information handling system of claim 8 , wherein, for at least one of the inquiry responses, the response values comprise a performance metric related to a currently executing instance of the particular container. 10. The information handling system of claim 9 , wherein the execution constraint indicates a region where the particular container is not permitted to execute. 11. The information handling system of claim 8 , wherein the execution constraint is selected from the group consisting of a number of central processing units (CPUs), a constraint on a physical location where the particular container can be deployed and a required proximity to at least one other container. 12. The information handling system of claim 8 , wherein the response values identify one or more time slots of available capacity for the particular container. 13. The information handling system of claim 12 , wherein the response values comprise an articulation of available capacity for each of the one or more time slots. 14. The information handling system of claim 8 , wherein the inquiry values and the response values are expressed in a markup language. 15. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising: receiving a trigger to deploy a particular container on cloud resources accessible thereto, wherein the cloud resources are provided by a plurality of cloud providers, wherein computer system and the plurality of cloud providers are configured to negotiate container deployment using an information exchange protocol; wherein the information exchange protocol comprises a preconfigured inquiry format a preconfigured inquiry-response format and a preconfigured scheduling format, the preconfigured inquiry format specifying an arrangement of inquiry fields, the preconfigured inquiry-response format specifying an arrangement of response fields, and the preconfigured scheduling format specifying an arrangement of scheduling fields; responsive to the trigger, generating a performance inquiry in relation to the particular container, wherein the performance inquiry comprises inquiry values corresponding to the arrangement of inquiry fields, wherein the
Logical partitioning of resources; Management or configuration of virtualized resources (specific details on emulation or internal functioning of virtual machines G06F9/455) · CPC title
using an interconnection network, e.g. matrix, shuffle, pyramid, star, snowflake · CPC title
Architectures of resource allocation · CPC title
Managing session states for stateless protocols; Signalling session states; State transitions; Keeping-state mechanisms · CPC title
involving the movement of software or configuration parameters (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.