Isolating virtual machine workloads within pods in a cluster environment

US12099863B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12099863-B2
Application numberUS-202117352494-A
CountryUS
Kind codeB2
Filing dateJun 21, 2021
Priority dateJun 21, 2021
Publication dateSep 24, 2024
Grant dateSep 24, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects include providing isolation between a plurality of containers in a pod that are each executing on a different virtual machine (VM) on a host computer. Providing the isolation includes converting a data packet into a serial format for communicating with the host computer. The converted data packet is sent to a router executing on the host computer. The router determines a destination container in the plurality of containers based at least in part on content of the converted data packet and routes the converted data packet to the destination container.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method comprising: providing isolation between a plurality of containers in a pod, wherein each of the plurality of containers are executing on a different virtual machine (VM) on a host computer, the providing isolation comprising: converting a data packet into a serial format for communicating with the host computer; and sending, by a first container of the plurality of containers, the converted data packet to a router executing on the host computer, wherein the router determines a destination container in the plurality of containers based at least in part on content of the converted data packet, and routes the converted data packet to the destination container, wherein none of the plurality of containers in the pod have access to resources of other containers of the plurality of containers in the pod. 2. The method of claim 1 , wherein one of the plurality of containers in the pod is addressable from outside of the pod via an external internet protocol (IP) address. 3. The method of claim 2 , wherein the plurality of containers in the pod are addressable by the host computer at a same loopback IP address. 4. The method of claim 1 , wherein none of the plurality of containers in the pod are in direct communication with any of the other containers in the pod. 5. The method of claim 1 , wherein all of the communication between the plurality of containers in the pod are indirect communications via the router. 6. The method of claim 1 , wherein the destination container, upon receipt of the converted data packet, sends the data packet to an IP address outside of the pod that is specified by the converted data packet. 7. The method of claim 1 , wherein prior to the converting, the data packet is in a TCP/IP format. 8. The method of claim 1 , wherein the serial format is vhost-vsock. 9. A system comprising: one or more processors for executing computer-readable instructions, the computer-readable instructions controlling the one or more processors to perform operations comprising: providing isolation between a plurality of containers in a pod, wherein each of the plurality of containers are executing on a different virtual machine (VM) on a host computer, the providing isolation comprising: converting a data packet into a serial format for communicating with the host computer; and sending, by a first container of the plurality of containers, the converted data packet to a router executing on the host computer, wherein the router determines a destination container in the plurality of containers based at least in part on content of the converted data packet, and routes the converted data packet to the destination container, wherein none of the plurality of containers in the pod have access to resources of other containers of the plurality of containers in the pod. 10. The system of claim 9 , wherein one of the plurality of containers in the pod is addressable from outside of the pod via an external internet protocol (IP) address. 11. The system of claim 10 , wherein the plurality of containers in the pod are addressable by the host computer at a same loopback IP address. 12. The system of claim 9 , wherein none of the plurality of containers in the pod are in direct communication with any of the other containers in the pod. 13. The system of claim 9 , wherein all communication between the plurality of containers in the pod are indirect communications via the router. 14. The system of claim 9 , wherein the destination container, upon receipt of the converted data packet, sends the data packet to an IP address outside of the pod that is specified by the converted data packet. 15. The system of claim 9 , wherein prior to the converting, the data packet is in a TCP/IP format. 16. The system of claim 9 , wherein the serial format is vhost-vsock. 17. A computer program product comprising a computer-readable storage medium having program instructions embodied therewith, the program instructions executable by one or more processors to cause the one or more processors to perform operations comprising: providing isolation between a plurality of containers in a pod, wherein each of the plurality of containers are executing on a different virtual machine (VM) on a host computer, the providing isolation comprising: converting a data packet into a serial format for communicating with the host computer; and sending, by a first container of the plurality of containers, the converted data packet to a router executing on the host computer, wherein the router determines a destination container in the plurality of containers based at least in part on content of the converted data packet, and routes the converted data packet to the destination container, wherein none of the plurality of containers in the pod have access to resources of other containers of the plurality of containers in the pod. 18. The computer program product of claim 17 , wherein one of the plurality of containers in the pod is addressable from outside of the pod via an external internet protocol (IP) address. 19. The computer program product of claim 18 , wherein the plurality of containers in the pod are addressable by the host computer at a same loopback IP address. 20. The computer program product of claim 17 , wherein none of the plurality of containers in the pod are in direct communication with any of the other containers in the pod.

Assignees

Inventors

Classifications

  • In-band adaptation of TCP data exchange; In-band control procedures · CPC title

  • Network integration; Enabling network access in virtual machine instances · CPC title

  • Isolation or security of virtual machine instances · CPC title

  • Hypervisor-specific management and integration aspects · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12099863B2 cover?
Aspects include providing isolation between a plurality of containers in a pod that are each executing on a different virtual machine (VM) on a host computer. Providing the isolation includes converting a data packet into a serial format for communicating with the host computer. The converted data packet is sent to a router executing on the host computer. The router determines a destination con…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F9/45558. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 24 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).