Configuration techniques for managing host operating systems and containerized applications instantiated therefrom
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MICROSOFT TECHNOLOGY LICENSING LLC
- Filing Date
- 2021-03-12
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]本文描述的实施例旨在利用容器化应用配置管理计算设备。例如,服务器处的移动设备管理器可以经由例如企业网络向计算设备提供配置设置。在计算设备上执行的主机操作系统确定并应用适用于主机操作系统的设置。存储配置设置以用于配置在计算设备上执行的容器化应用。例如,当主机操作系统启动新的容器化应用时,容器化应用将取回配置设置,并确定和应用适用于容器化应用的设置。将配置设置应用到主机操作系统和容器化应用的结果将被合并并且被发送到移动设备管理器。例如,主机操作系统和容器化应用可以实现这些设置,以符合企业策略(例如,数据和/或安全策略)。
Smart Images

Figure CN115668139B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure relate to configuration techniques for managing host operating systems and containerized applications instantiated therefrom. Background Technology
[0002] Mobile Device Management (MDM) is a method to ensure employees remain productive and do not violate company policies. Many organizations use MDM products / services and / or other management entities to control their employees' activities. These products, services, and / or entities primarily handle company data segregation, securing email, protecting company documents on devices, enforcing company policies, and integrating and managing mobile devices, including various types of laptops and handheld devices. Such technologies mitigate various security risks by ensuring that computing devices issued by the organization and third-party computing devices allowed access to the organization's network are configured in accordance with the organization's data and security policies. Summary of the Invention
[0003] This invention provides a simplified overview of some concepts, which will be further described in the detailed description below. This invention is not intended to identify key or essential features of the claimed object, nor is it intended to limit the scope of the claimed object.
[0004] The embodiments described herein are designed to manage computing devices using containerized application configuration. For example, a mobile device manager on a server may provide configuration settings to the computing device via, for example, an enterprise network. The host operating system running on the computing device determines and applies settings applicable to the host operating system. The configuration settings are stored for configuring the containerized application running on the computing device. For example, when the host operating system launches a new containerized application, the containerized application retrieves the configuration settings and determines and applies settings applicable to the containerized application. The results of applying the configuration settings to the host operating system and the containerized application are merged and sent to the mobile device manager. For example, the host operating system and the containerized application may implement these settings to conform to enterprise policies (e.g., data and / or security policies).
[0005] Further features and advantages of the invention, as well as the structure and operation of various embodiments thereof, are described in detail below with reference to the accompanying drawings. It is important to note that the invention is not limited to the specific embodiments described herein. These embodiments are presented herein for illustrative purposes only. Other embodiments will be apparent to those skilled in the art based on the teachings contained herein. Attached Figure Description
[0006] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments and, together with the specification, further serve to explain the principles of the embodiments and enable those skilled in the art to make and use the embodiments.
[0007] Figure 1 A block diagram of a system for managing and configuring one or more computing devices, according to an example embodiment, is depicted.
[0008] Figure 2 A block diagram of a system for managing and configuring one or more computing devices according to an example embodiment is depicted. Figure 1 Further detailed examples of the system.
[0009] Figure 3 A flowchart is depicted illustrating an example method implemented by a computing device, according to an example embodiment, for configuring a host operating system and a containerized application running thereon.
[0010] Figure 4 A flowchart is depicted for an example method, according to an example embodiment, for returning the result of applying configuration settings on a computing device.
[0011] Figure 5 A flowchart is depicted according to an example method of an example embodiment, which is used to provide a configuration settings request from a containerized application to a mobile device manager.
[0012] Figure 6 A system block diagram is depicted according to an embodiment for determining whether a computing device remains compliant with compliance rules.
[0013] Figure 7 This is a block diagram of an exemplary user device that can be implemented in the embodiments.
[0014] Figure 8 This is a block diagram of an example computing device that can be used to implement the embodiments.
[0015] The features and advantages of the invention will become more apparent from the detailed description below when taken in conjunction with the accompanying drawings, wherein similar reference numerals consistently identify corresponding elements. In the drawings, similar reference numerals generally denote identical, functionally similar, and / or structurally similar elements. The first appearance of an element in a figure is indicated by the leftmost digit of the corresponding reference numeral. Detailed Implementation
[0016] I. Introduction This specification and accompanying drawings disclose one or more embodiments incorporating the features of the present invention. The scope of the invention is not limited to the disclosed embodiments. The disclosed embodiments are merely examples of the invention, and modifications to the disclosed embodiments are also included in the invention. The embodiments of the invention are defined by the appended claims.
[0017] References to "an embodiment," "embodiment," and "example embodiment," etc., in this specification indicate that the described embodiment may include specific features, structures, or characteristics, but each embodiment does not necessarily include those specific features, structures, or characteristics. Furthermore, these phrases do not necessarily refer to the same embodiment. Moreover, when a specific feature, structure, or characteristic is described in connection with an embodiment, those skilled in the art will recognize that the feature, structure, or characteristic can be implemented in conjunction with other embodiments, whether explicitly described or not.
[0018] Numerous exemplary embodiments are described below. It is important to note that any section / heading provided herein is not restrictive. Embodiments of any type are described in this document and may be included in any section / heading. Furthermore, embodiments disclosed in any section / heading may be combined in any manner with any other embodiments described in the same section / heading and / or different sections / headings.
[0019] II. Systems and Methods for Configuring and Managing Computing Devices Using Containerized Applications The embodiments described herein are designed to manage computing devices using containerized application configuration. For example, a mobile device manager on a server may provide configuration settings to the computing device via, for example, an enterprise network. The host operating system running on the computing device determines and applies settings applicable to the host operating system. The configuration settings are stored to configure the containerized application running on the computing device. For example, when the host operating system launches a new containerized application, the containerized application retrieves the configuration settings and determines and applies settings applicable to the containerized application. The results of applying the configuration settings to the host operating system and the containerized application are merged and sent to the mobile device manager. For example, the host operating system and the containerized application may implement these settings to conform to enterprise policies (e.g., data and / or security policies).
[0020] Containerized applications do not obtain configuration settings directly from the mobile device manager; instead, they utilize configuration settings provided via the host operating system. Therefore, the host operating system acts as an agent to manage containerized applications on behalf of the mobile device manager. By having the host operating system act as an agent, the mobile device manager does not need to know about each containerized application and is relieved of the burden of individually managing each containerized application running on the computing device, as the mobile device manager does not need to provide configuration settings to the computing device every time a new containerized application is launched. This advantageously reduces network traffic between the computing device and the mobile device manager, thereby freeing up network bandwidth for the enterprise network. Furthermore, both the mobile device manager and the computing device utilize fewer computing resources (e.g., processing power, memory, power, etc.). For example, the mobile device manager does not need to provide a large number of configuration settings for each instance of a containerized application at different times, and the computing device does not need to provide a large number of requests for configuration settings for each containerized application running on it. Moreover, each time configuration settings are applied to the host operating system or a specific containerized application, the computing device does not need to provide the result of the application configuration settings. Instead, the computing device provides the mobile device manager with a merged version of the result.
[0021] The reduction in network transactions between computing devices and mobile device managers effectively reduces the configuration time of computing devices, enabling users to start using their devices more quickly.
[0022] Figure 1 This is a block diagram of a system 100 for managing and configuring one or more computing devices according to an example embodiment. Figure 1 As shown, system 100 includes server 102 and one or more computing devices 104, which are communicatively coupled via network 106. Network 106 may include one or more networks, such as local area network (LAN), wide area network (WAN), enterprise network, Internet, etc., and may include one or more wired and / or wireless portions. As used herein, the term "enterprise" broadly refers to any of various organizational types, including corporations, non-profit organizations, and government agencies. An enterprise network includes a dedicated computer network established by an enterprise for the purpose of interconnecting enterprise devices (e.g., computing devices 104) at one or more enterprise locations with other enterprise devices, and enabling enterprise devices to access and / or share computing resources. Users of computing devices 104 may be referred to herein as "enterprise users" or simply "users." Each of the computing devices 104 may include, for example, but not limited to, desktop computers, laptops, tablets, netbooks, smartphones, etc. References will follow below. Figure 7 and Figure 8 Other examples describing computing devices (multiple) 104.
[0023] Server 102 can be configured to manage each(s) of computing devices(s) 104 according to policies (e.g., data and / or security policies). Policies can be specified by the enterprise. Server 102 may also be referred to as a Mobile Device Manager (MDM). Policies can be specified according to one or more compliance rules. For example, server 102 may include a compliance engine 108. The compliance engine 108 can determine the configuration settings 110 to be provided to a specific computing device(s) 104 and provide it with the determined configuration(s). The determined configuration settings may comply with the (multiple) compliance rules. The (multiple) compliance rules can be specified by an enterprise administrator (e.g., an IT administrator or other personnel within the enterprise who may be responsible for deploying, maintaining, and / or configuring (multiple) computing devices(s) 104 on behalf of enterprise users). Configuration settings 110 can be maintained by server 102 (e.g., ...). Figure 1 (As shown), it can also be stored in a data storage device (not shown) that is communicatively coupled to server 102.
[0024] Configuration settings 110 can specify one or more configuration settings for a specific computing device and / or a specific user of each of the multiple computing devices 104. Therefore, each of the multiple computing devices 104 can be associated with multiple configuration settings 110. For example, a first configuration of configuration settings 110 can be associated with a first user of a specific computing device, and a second configuration of configuration settings 110 can be associated with a second user of a specific computing device. Examples of configuration settings 110 include, but are not limited to, one or more encryption settings to be implemented by the multiple computing devices 104, one or more other security settings to be implemented by the computing devices 104, one or more network settings to be implemented by the multiple computing devices 104, one or more application behavior settings affecting the behavior of applications executing on the multiple computing devices 104 (e.g., containerized application 114), minimum versions of at least one application or operating system required to be installed on the multiple computing devices 104, etc. The multiple encryption settings can specify whether storage devices included in the multiple computing devices 104 are encrypted (e.g., by an encryption program, such as, but not limited to, BitLocker™). Multiple security settings can specify the password policies enforced by computing device 104 (e.g., setting the password length to at least 10 characters, 12 characters, etc.), whether code signing should be implemented by computing device 104, whether a Trusted Platform Module (TPM) should be implemented by computing device 104, whether an anti-malware application should be installed and / or activated on computing device 104, and whether a firewall application should be installed and / or activated on computing device 104, etc. Multiple network settings can specify network proxy settings to be implemented by computing device 104, Quality of Service (QoS) settings to be implemented by computing device 104, network isolation settings to be implemented by computing device 104, etc. Note that the above configuration settings are purely exemplary, and other configuration settings can be used.
[0025] Configuration setting 110 can take any suitable form. According to an embodiment, configuration setting 110 can be represented by an Extensible Markup Language (XML) file, which includes a payload associated with configuration setting 110 and a corresponding Uniform Resource Identifier (URI) for downloading and processing the payload.
[0026] Each of the (multiple) computing devices 104 is configured to run a host operating system 112. The host operating system 122 is configured to launch applications (such as containerized application 114) via containers. A container is a standard unit of executable software that packages an application's program code and all its dependencies required for execution, allowing the application to run quickly and reliably from one computing environment to another. Examples of containers include, but are not limited to, MSIX containers (for running MSIX applications), Universal Windows Platform (UWP) containers (for running UWP applications), and Win32 containers (for running Win32 applications). By running applications via containers, the security and performance of the computing device running containerized application 114 can be improved. Each container can run independently as a guest operating system secondary to the host operating system 112. Each guest operating system can have its own kernel, registry, and drivers.
[0027] Host operating system 112 is configured to receive configuration settings 110 from server 102. Host operating system 112 determines configuration settings based on the applicable configuration settings 110 and configures accordingly. Host operating system 112 also makes configuration settings 110 available to containerized application 114. Instead of obtaining configuration settings 114 directly from server 102, containerized application 114 utilizes configuration settings 110 provided via host operating system 112, determines applicable configuration settings from them, and configures itself accordingly. Therefore, host operating system 112 acts as a proxy to manage containerized application 114 on behalf of server 102.
[0028] By having the host operating system 112 act as a proxy, server 102 is relieved of the burden of managing each containerized application 114 individually. Therefore, server 102 does not need to know about containerized applications 114 and provide configuration settings to computing devices(s) 104 each time a new containerized application is launched. Instead, whenever a containerized application is launched, it obtains its configuration settings through the host operating system 112. This helps reduce network traffic between computing devices(s) 104 and server 102, as well as the load experienced by computing devices(s) 104 and server 102.
[0029] After the host operating system 112 and containerized application 114 apply configuration settings 110, the (multiple) computing devices 104 provide a response to the server 102, indicating the result of applying the configuration settings on it. For example, the result may indicate whether the application of configuration settings 114 was successful or failed. Upon receiving a response specifying that each configuration setting 110 has been successfully applied from a particular computing device (multiple) of computing devices 104, the compliance engine 108 specifies that the computing device receiving the response complies with (multiple) compliance rules and that the computing device has access to the resources of network 106.
[0030] Upon receiving a response indicating that one or more configuration settings were not successfully applied, compliance engine 108 may determine that a particular computing device is non-compliant and / or block such computing device from accessing resources accessible via network 160. Such resources include, but are not limited to, email servers, data repositories, application servers, etc. Access to such resources may be blocked until the computing device(s) 104 complies with requirements.
[0031] In an embodiment, Figure 1 System 100 can be implemented in various ways. For example, Figure 2 A detailed block diagram of system 200 according to an example embodiment is depicted. System 200 is an example of system 100. Figure 2 As shown, system 200 includes server 202 and computing device 204, which are communicatively coupled via network 206. (See reference above.) Figure 1 The server 202, computing device 204, and network 206 are examples of server 102, computing device 104, and network 106, respectively. Figure 2 As shown, server 202 includes compliance engine 208 and configuration settings 210, which are as described in the reference above. Figure 1 Examples of the compliance engine 108 and configuration settings 110 are provided. The computing device 204 includes a host operating system 212 and containerized applications 214, as described above. Figure 1 Examples of the host operating system 112 and containerized application 114.
[0032] The host operating system 212 includes a configuration agent 216, a local data storage 218, and a result merger 220. The configuration agent 215 is configured to receive configuration settings 210 from the server 202 via network 206. According to one embodiment, the configuration settings 210 provided by the server 210 are initiated by the configuration agent 217. For example, the configuration agent 216 may query (or “check in”) the server 202 to determine whether the server 202 includes configuration settings 210 to be applied to the computing device 204. The configuration agent 216 may periodically query the server 202. However, the embodiments described herein are not so limited. For example, the configuration agent 216 may query the server 202 in response to a user's command. According to another embodiment, the configuration settings 210 provided by the server 210 are initiated by the server 202. For example, the compliance engine 208 may determine that new configuration settings need to be provided to the computing device 204 and provide (or “push”) these settings to the configuration agent 216.
[0033] Upon receiving configuration settings 210, configuration agent 216 determines one or more settings of configuration settings 210 applicable to host operating system 212 and applies them to the corresponding operating system components (e.g., kernel, registry, drivers, etc.) and / or applications of host operating system 121. For example, configuration agent 216 may apply one or more filtering rules 226 to determine whether a specific setting of configuration settings 210 applies to host operating system 212. Each filtering rule may include information about whether a specific configuration setting in configuration settings 210 applies to host operating system 212, containerized application 214, or both host operating system 212 and containerized application 214. For example, a rule may include an identifier for an antivirus application (e.g., Windows® Defender, published by Microsoft Corporation of Redmond, Washington), and an instruction on whether to configure an antivirus application for host operating system 121, containerized application 214, or both host operating system 212 and containerized application 214. According to an embodiment, the indication may include values, where value "1" specifies that the antivirus application should be configured for host operating system 121, value "2" specifies that the antivirus application should be configured for containerized application 214, and value "3" specifies that the antivirus application should be configured for both host operating system 212 and containerized application 214. Configuration agent 216 analyzes the indication for each filtering rule to determine whether the corresponding configuration setting of configuration setting 210 should be applied to host operating system 121.
[0034] According to an embodiment, filtering rule 226 may be provided by and / or subsequently updated by filtering rule service 228. Figure 2 As shown, filtering rule service 288 can be executed on server 230, which is communicatively coupled to computing device 204 via network 206. Alternatively, filtering rule service 228 can be executed on server 202. Filtering rule service 228 can be configured to periodically provide updated filtering rules to computing device 204. This advantageously provides flexibility in configuring computing device 204, as the configuration requirements of computing device 204 may change over time. Examples of filtering rule service 228 include, but are not limited to, Microsoft® OneSettings, published by Microsoft Corporation of Redmond, Washington.
[0035] Configuration agent 216 stores configuration settings 210 and filtering rules 226 in local data storage 218 maintained by the host operating system 212. Configuration agent 218 also stores the results of applying the applicable configuration settings of configuration settings 210 (displayed as result 234) in local data storage 318. For example, result 234 can indicate whether the application of each applicable setting of configuration settings 210 was successful or failed.
[0036] Local data storage 218 is integrated as part of computing device 204. Local data storage 218 can be any type of physical memory and / or storage device (or part thereof) described herein, and / or any type that can be understood by those skilled in the art having advantages over this invention. Local data storage 218 is accessible to containerized application 214.
[0037] The containerized application 214 includes a configuration agent 222, a configuration engine 232, and a local data storage 224. When the host operating system 212 instantiates (or starts) the containerized application software 214, the configuration engine 232 retrieves configuration settings 210 and filtering rules 226 from the local data storage 218 and stores the configuration settings 210 and filtering rules 226 in the local data storage 224 maintained by the containerized application 214. The local data storage 224 is integrated as part of the computing device 204. The local data storage 224 can be any type of physical memory and / or storage device (or part thereof) described herein, and / or any type that can be understood by a person skilled in the art(s) with the advantages of this disclosure. Configuration agent 222 is configured to retrieve configuration settings 210 and filtering rules 226 from local data storage 224. Configuration agent 222 determines one or more settings of configuration settings 210 applicable to containerized application 214 and applies them to the appropriate guest operating system components (e.g., kernel, registry, drivers, etc.) of containerized application 214. For example, configuration agent 222 may apply filtering rules(s)226 to determine whether a specific setting of configuration setting 210 applies to containerized application 214. Each filtering rule may include information about whether a specific configuration setting of configuration setting 210 applies to host operating system 212, containerized application 214, or both host operating system 212 and containerized application 214. Configuration agent 222 analyzes the indication of each filtering rule to determine whether the corresponding configuration setting of configuration setting 210 will be applied to containerized application 214.
[0038] Configuration agent 222 also stores the results of applying the applicable configuration settings of configuration setting 210 (as shown in result 236) in local data storage 224. For example, result 236 can indicate whether each applicable setting of configuration setting 110 was successful or failed.
[0039] Configuration engine 232 is configured to retrieve result 236 from local data store 224 and store result 236 in local data store 218. Result merger 220 is configured to retrieve result 234 and result 236 from local data store 217. Result merger 220 merges result 234 and result 236 to generate merged result 242 and provides merged result 242 to configuration agent 216. Configuration agent 216 provides merged result 242 to server 202 via response 240.
[0040] If response 240 contains a result indicating that the specified configuration settings 210 have been successfully applied to computing device 204, then compliance engine 208 designates computing device 208 as compliant, and computing device 204 is enabled to access resources of network 206.
[0041] If response 240 includes a result indicating that one or more configuration settings were not successfully applied, compliance engine 210 may determine that computing device 204 is non-compliant and / or prevents computing device 204 from accessing resources accessible via network 206. Based on the result, compliance engine 210 may also provide computing device 204 with additional configuration settings to be applied by host operating system 212 and / or containerized applications 214. For example, the result may indicate that a specific configuration setting was not applied to computing device 204 due to incompatibility between the configuration setting and computing device 204. In response, compliance engine 210 may provide alternative configuration settings to computing device 204.
[0042] According to an embodiment, containerized application 214 can initiate a configuration settings request. Since server 202 is unaware of containerized application 214, host operating system 212 provides (or forwards) the request on behalf of containerized application software 214. For example, configuration agent 222 can provide a request specifying the requested configuration settings to configuration agent 216 of host operating system 212, and configuration agent 216 forwards the request to server 202. In response to receiving the request, compliance engine 208 provides the requested configuration settings to configuration agent 216. Configuration agent 218 stores the configuration result in local data storage 218. Configuration engine 232 of containerized application 214 retrieves the configuration settings from local data storage 218 and stores the configuration settings in local data storage 224 of containerized application 214. Configuration agent 222 retrieves the configuration settings and applies them to containerized application 214. Further details regarding containerized application requests for configuration settings are referenced below. Figure 5 and Figure 6 Described.
[0043] Therefore, computing devices can be managed and configured in a variety of ways. For example, Figure 3A flowchart 300 depicts an example method implemented by a computing device, according to an example embodiment, for configuring a host operating system and a containerized application running thereon. Further reference will continue. Figure 2 The system 200 describes the method of flowchart 300, although the method is not limited to this implementation. According to... Figure 2 The flowchart 300 and the discussion of system 200, as well as other structural and operational embodiments, will be apparent to those skilled in the art.
[0044] like Figure 3 As shown, the method in flowchart 300 begins at step 302, where multiple configuration settings for the computing device are received from the server. For example, refer to... Figure 2 The configuration agent 216 of the host operating system 212 running on computing device 204 receives configuration settings 210 from server 202 via network 206. Server 202 may be a mobile device manager.
[0045] In step 304, a first subset of the configuration settings from the plurality of configuration settings is applied to the host operating system running on the computing device. For example, refer to Figure 2 The configuration agent 216 of the host operating system 212 applies the configuration settings 210 to the host operating system 121.
[0046] According to one or more embodiments, a first filtering rule is applied to multiple configuration settings to determine a first subset of the configuration settings. The first subset of configuration settings applies to a first operating system. For example, refer to... Figure 2 Configuration agent 216 applies filtering rule 226 to configuration settings 210 to determine a subset of configuration settings 210 applicable to host operating system 212. Local data storage 218 stores filtering rule 226.
[0047] In step 306, the configuration settings are stored in a local data store. For example, refer to... Figure 2 The configuration agent 216 stores the configuration settings 210 in the local data storage 218.
[0048] In step 308, at least a second subset of configuration settings from a plurality of configuration settings is retrieved from the local data store by a containerized application instantiated by the host operating system and executed on the computing device. For example, refer to Figure 2 The configuration engine 232 of the containerized application 214 retrieves configuration settings 210 from the local data storage 218 and stores the configuration settings 210 in the local data storage 224. The configuration engine 232 can retrieve all configuration settings 210. Alternatively, the configuration engine 232 can retrieve and filter rules 226, and use the filtering rules 232 to retrieve a subset of the configuration settings 210 applicable to the containerized application 214.
[0049] In step 310, a second subset of the configuration settings from the multiple configuration settings is applied to the containerized application. For example, refer to... Figure 2 The configuration agent 222 of the containerized application 214 retrieves the configuration settings 210 from the local data storage 224 and applies a second subset of the configuration settings 210 to the containerized application 214.
[0050] According to one or more embodiments, the multiple configuration settings include at least one of the following: security settings to be implemented for a computing device, network settings to be implemented for a computer device, encryption settings to be implemented for a computing device, or application behavior settings to be implemented for a containerized application.
[0051] According to one or more embodiments, a second filtering rule is applied to multiple configuration settings to determine a second subset of the configuration settings. This second subset of configuration settings is suitable for containerized applications. For example, refer to... Figure 2 Configuration engine 232 retrieves filtering rule 226 from local data storage 218. Configuration agent 222 retrieves filtering rule 226 and applies it to configuration settings 210 to determine a subset of configuration settings 210 suitable for containerized application 214.
[0052] According to one or more embodiments, the host operating system receives a first filtering rule and a second filtering rule from a filtering rule service over a network. For example, see reference... Figure 2 The host operating system 212 receives filtering rules 226 from the filtering rule service 228 executed on the server 230 via the network 206.
[0053] Figure 4 A flowchart 400 depicts an example method, according to an example embodiment, for returning the result of applying configuration settings on a computing device. The method in flowchart 400 will continue to be referenced. Figure 2 The system 200 is described, although the method is not limited to this implementation. According to... Figure 2 The flowchart 400 and the discussion of system 200, as well as other structural and operational embodiments, will be apparent to those skilled in the art.
[0054] like Figure 4 As shown, the method in flowchart 400 begins at step 402, where a first result of the application of a first subset of the configuration settings is stored in local data storage. The first result indicates whether the application of the first subset of the configuration settings was successful. For example, refer to... Figure 2 The configuration agent 216 stores the application results 234 of the first subset of the configuration settings 210 in the local data storage 218.
[0055] In step 404, the second result of applying the second subset of configuration settings is stored in local data storage. The second result indicates whether the application of the second subset of configuration settings was successful. For example, refer to... Figure 2 The configuration agent 222 of the containerized application 214 stores the result 236 of the application of the second subset of the configuration settings 210 in the local data storage 224. The configuration engine 232 retrieves the result 236 from the local data storage 244 and saves the result 236 in the local data storage 218.
[0056] In step 406, the first and second results are merged to generate a merged result. For example, refer to... Figure 2 The result merger 220 retrieves results 234 and 236 from the local data storage 218 and merges results 234 and 236 to generate merged result 242.
[0057] In step 408, the merged result is provided to the server via the network. For example, refer to... Figure 2 Merger 220 provides merge result 242 to configuration agent 216, and configuration agent 216 provides merge result 242 to server 202 via network 206 and response 240.
[0058] According to one or more embodiments, based on the merging result, additional configuration settings are received from the server via a network. For example, refer to... Figure 2 Based on the merge result 242, server 202 can determine additional configuration settings for computing device 204 and provide them to computing device 204 via network 206. Computing device 204 can apply the additional configuration settings according to flowchart 300 (as described above).
[0059] Figure 5 A flowchart 500 depicts an example method according to an example embodiment, which is used to provide a configuration settings request from a containerized application to a mobile device manager. Reference will now be made to... Figure 6 The method of describing flowchart 500 is not limited to the implementation described therein. Figure 6 This is a block diagram of a system 600 for configuring a computing device to conform to an example embodiment. (e.g.) Figure 6 As shown, system 600 includes server 602, server 630, and computing device 604, which are communicatively coupled via network 606. (See above reference.) Figure 2 As described above, server 602, server 630, computing device 604, and network 606 are examples of server 202, server 230, computing device 204, and network 206. (See above reference.) Figure 2 As described above, server 602 includes compliance engine 608 and configuration settings 610, which are examples of compliance engine 208 and configuration settings 210. (See above reference...) Figure 2 The server 630 includes a filtering rule service 628, which is an example of the filtering rule service 228. (See above reference.) Figure 2 The computing device 604 includes a host operating system 612 and a containerized application 614, which are examples of the host operating system 612 and the containerized application 614. The host operating system 612 includes a configuration agent 616, filtering rules 626, a result merger 620, and local data storage 616, which are examples of the configuration agent 616, filtering rules 226, result merger 220, and local data storage 618. The local data storage 618 stores configuration settings 610, filtering rules 626, results 634, and results 636. (Refer to the above text.) Figure 2 As stated above, results 634 and 636 are examples of results 234 and 236. Figure 2 The containerized application 614 includes a configuration agent 622, a configuration engine 632, and a local data storage 624, which are examples of the configuration agent 622, configuration engine 632, and local data storage 624. The local data storage 624 stores configuration settings 610, filtering rules 626, and results 636. Figure 6 The discussion of flowchart 500 and system 600, as well as other structural and operational embodiments, will be obvious to those skilled in the art(s).
[0060] like Figure 5 As shown, the method in flowchart 500 begins at step 502, where the containerized application provides a request to the host operating system for additional configuration settings. For example, refer to... Figure 6 The configuration agent 222 of the containerized application can provide a request 642 for additional configuration settings to the configuration agent 216 of the host operating system 212.
[0061] In step 504, the host operating system forwards the request to the server over the network. For example, refer to... Figure 6 The configuration agent 616 forwards request 642 to server 602 via network 606.
[0062] In step 506, the host operating system receives additional configuration settings from the server via the network. For example, refer to... Figure 6 Configuration agent 216 receives additional configuration settings (e.g., configuration settings 610) from server 602 via network 606.
[0063] In step 508, the additional configuration settings are stored in the local data store. For example, refer to... Figure 6 Configuration agent 216 stores additional configuration settings in local data storage 618.
[0064] In step 510, the containerized application retrieves additional configuration settings from its local data store. For example, refer to... Figure 6 Configuration engine 632 retrieves additional configuration settings (e.g., configuration settings 610) from local data store 618 and stores the settings in local data store 624. Configuration agent 622 retrieves settings from local database 624 and applies these settings to containerized application 214.
[0065] III. Examples of Mobile and Fixed Equipment Implementation The above systems and methods, including references Figures 1 to 6The described device management and configuration embodiments can be implemented in hardware or in hardware that combines one or more of software and / or firmware. For example, server 102, compliance engine 108, (multiple) computing devices 104, host operating system 112, containerized application 114, server 202, compliance engine 208, computing device 204, host operating system 212, containerized application 214, configuration agent 216, local data storage 218, result merger 220, configuration agent 222, local data storage 224, configuration engine 232, server 602, compliance engine 608, computing device 604, host operating system 612, containerized application 614, configuration agent 616, local data storage 618, result merger 620, configuration agent 622, local data storage 624, configuration engine 632 and / or each of the components described therein, as well as flowcharts 300, 400 and / or 500, are each implemented as computer program code / instructions configured to execute in one or more processors and stored in a computer-readable storage medium. Alternatively, server 102, compliance engine 108, (multiple) computing devices 104, host operating system 112, containerized application 114, server 202, compliance engine 208, computing device 204, host operating system 212, containerized application 214, configuration agent 216, local data storage 218, result merger 220, configuration agent 222, local data storage 224, configuration engine 232, server 602, compliance engine 608, computing device 604, host operating system 612, containerized application 614, configuration agent 616, local data storage 618, result merger 620, configuration agent 622, local data storage 624, configuration engine 632 and / or each of the components described therein, as well as flowcharts 300, 400 and / or 500, can be implemented as hardware logic / electrical circuitry. In the embodiments, server 102, compliance engine 108, (multiple) computing devices 104, host operating system 112, containerized application 114, server 202, compliance engine 208, computing device 204, host operating system 212, containerized application 214, configuration agent 216, local data storage 218, result merger 220, configuration agent 222, local data storage 224, configuration engine 232, server 602, compliance engine 608, computing device 604, host operating system 612, containerized application 614, configuration agent 616, local data storage 618, result merger 620, configuration agent 622, local data storage 624, configuration engine 632 and / or each of the components described herein, as well as flowcharts 300, 400 and / or flowchart 500, may be implemented in one or more SoCs (System-on-Chip).A SoC may include an integrated circuit chip that includes one or more processors (e.g., a central processing unit (CPU), a microcontroller, a microprocessor, a digital signal processor (DSP), etc.), memory, one or more communication interfaces and / or further circuitry, and may optionally execute received program code and / or include embedded firmware to perform functions.
[0066] Figure 7 A block diagram of an exemplary mobile device 700 is shown, including various optional hardware and software components, typically shown as component 702. Server 102, compliance engine 108, (multiple) computing devices 104, host operating system 112, containerized application 114, server 202, compliance engine 208, computing device 204, host operating system 212, containerized application 214, configuration agent 216, local data storage 218, result merger 220, configuration agent 222, local data storage 224, configuration engine 232, server 602, compliance engine 608, computing device 604, host operating system 612, containerized application 614, configuration agent 616, local database 618, result merger 620, configuration agent 622, local data storage 624, configuration engine 632, and / or each component described therein, as well as flowcharts 300, 400, and / or flowchart 500, may be implemented as component 702 included in the mobile device embodiment, along with additional and / or alternative features / elements known to those skilled in the art. It should be noted that, for ease of illustration, any one of components 702 may communicate with any other part of component 702, although not all connections are shown. Mobile device 700 may be any of the various mobile devices described or mentioned elsewhere herein or otherwise known (e.g., mobile phone, smartphone, handheld computer, personal digital assistant (PDA), etc.), and may allow wireless bidirectional communication with one or more mobile devices via one or more communication networks 704 (e.g., cellular or satellite networks) or using a local area network or wide area network.
[0067] The mobile device 700 shown may include a controller or processor, referred to as processor circuitry 710, for performing tasks such as signal encoding, image processing, data processing, input / output processing, power control, and / or other functions. Processor circuitry 710 is an electrical and / or optical circuit implemented as a central processing unit (CPU), microcontroller, microprocessor, and / or other physical hardware processor circuitry within one or more physical hardware circuitry device elements and / or integrated circuit devices (semiconductor material chips or molds). Processor circuitry 710 can execute program code stored in a computer-readable medium, such as program code for one or more applications 714, operating system 712, any program code stored in memory 720, etc. Operating system 712 can control the allocation and use of component 702 and support one or more applications 714 (also referred to as "applications," "apps," etc.). Applications 714 may include common mobile computing applications (e.g., email applications, calendars, contact managers, web browsers, messaging applications) and any other computing applications (e.g., word processing applications, map applications, media player applications).
[0068] As shown in the figure, mobile device 700 may include memory 720. Memory 720 may include non-removable memory 722 and / or removable memory 724. Non-removable memory 722 may include RAM, ROM, flash memory, hard disk, or other known memory storage technologies. Removable memory 724 may include flash memory or a Subscriber Identity Module (SIM) card known in GSM communication systems, or other known memory storage technologies such as a "smart card." Memory 720 may be used to store data and / or code running operating system 712 and application 714. Example data may include web pages, text, images, sound files, video data, or other datasets that will be sent to and / or received from one or more network servers or other devices via one or more wired or wireless networks. Memory 720 may be used to store user identifiers (e.g., International Mobile Subscriber Identity (IMSI)) and device identifiers (e.g., International Mobile Equipment Identity (IMEI)). Such identifiers may be transmitted to a network server to identify users and devices.
[0069] The memory 720 can store numerous programs. These programs include an operating system 712, one or more application programs 714, and other program modules and program data. Examples of such application programs or program modules may include, for example, computer program logic (e.g., computer program code or instructions) for implementing the system described above, including references. Figures 1-6 The described implementation example of equipment compliance management.
[0070] The mobile device 700 may support one or more input devices 730, such as a touch screen 732, a microphone 734, a camera 736, a physical keyboard 738 and / or a trackball 740, and one or more output devices 750, such as a speaker 752 and a display 754.
[0071] Other possible output devices (not shown) may include piezoelectric or other tactile output devices. Some devices may provide more than one input / output function. For example, touchscreen 732 and display 754 may be combined in a single input / output device. Input device 730 may include a natural user interface (NUI).
[0072] As understood in the art, the (multiple) wireless modems 760 may be coupled to (multiple) antennas (not shown) and may support bidirectional communication between the processor circuitry 710 and external devices. The (multiple) modems 760 are generally shown and may include a cellular modem 766 for communicating with a mobile communication network 704 and / or other radio-based modems (e.g., Bluetooth 764 and / or Wi-Fi 762). The cellular modem 766 may be configured to enable telephone calls (and optionally transmit data) according to any suitable communication standard or technology (such as GSM, 3G, 4G, 5G, etc.). Typically, at least one wireless modem 760 is configured to communicate with one or more cellular networks, such as a GSM network for data and voice communication within a single cellular network, between cellular networks, or between a mobile device and the Public Switched Telephone Network (PSTN).
[0073] The mobile device 700 may also include at least one input / output port 780, a power supply 782, a satellite navigation system receiver 784 (e.g., a Global Positioning System (GPS) receiver), an accelerometer 786, and / or a physical connector 790, which may be a USB port, an IEEE 1394 (FireWire) port, and / or an RS-232 port. The components 702 shown are not essential or all included; as those skilled in the art will recognize, any component may be absent, and other components may be additionally present.
[0074] also, Figure 8Exemplary implementations of computing device 800 are depicted, wherein embodiments may be implemented including server 102, compliance engine 108, (multiple) computing devices 104, host operating system 112, containerized application 114, server 202, compliance engine 208, computing device 204, host operating system 212, containerized application 214, configuration agent 216, local data storage 218, result merger 220, configuration agent 222, local data storage 224, configuration engine 232, server 602, compliance engine 608, computing device 604, host operating system 612, containerized application 614, configuration agent 616, local data storage 618, result merger 620, configuration agent 622, local database 624, configuration engine 632, and / or each component described herein, as well as flowcharts 300, 400, and / or flowchart 500. The description of computing device 800 provided herein is for illustrative purposes and is not intended to be limiting. As will be known to those skilled in the art, embodiments may be implemented in other types of computer systems.
[0075] like Figure 8 As shown, computing device 800 includes one or more processors (referred to as processor circuitry 802), system memory 804, and a bus 806 that couples various system components, including system memory 804, to processor circuitry 802. Processor circuitry 802 is an electrical and / or optical circuit implemented as a central processing unit (CPU), microcontroller, microprocessor, and / or other physical hardware processor circuitry in one or more physical hardware circuitry device elements and / or integrated circuit devices (semiconductor material chips or molds). Processor circuitry 802 can execute program code stored in a computer-readable medium, such as program code for operating system 830, application program 832, other programs 834, etc. Bus 806 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using various bus architectures. System memory 804 includes read-only memory (ROM) 808 and random access memory (RAM) 810. Basic input / output system 812 (BIOS) is stored in ROM 808.
[0076] The computing device 800 also includes one or more of the following drives: a hard disk drive 814 for reading and writing to a hard disk, a disk drive 816 for reading or writing to a removable disk 818, and an optical disc drive 820 for reading or reading a removable optical disc 822 (e.g., a CD-ROM, DVD-ROM, or other optical media). The hard disk drive 814, disk drive 816, and optical disc drive 820 are connected to the bus 806 via a hard disk drive interface 824, a disk drive interface 826, and an optical disc drive interface 828, respectively. The drives and their associated computer-readable media provide the computer with non-volatile storage of computer-readable instructions, data structures, program modules, and other data. While hard disks, removable disks, and removable optical discs have been described, other types of hardware-based computer-readable storage media can be used to store data, such as flash memory cards, digital video disks, RAM, ROM, and other hardware storage media.
[0077] Many program modules may be stored on a hard disk, magnetic disk, optical disk, ROM, or RAM. These programs include an operating system 830, one or more application programs 832, other programs 834, and program data 836. For example, application program 831 or other program 836 may include computer program logic (e.g., computer program code or instructions) for implementing the system described above, including references. Figures 1-6 The described device management and configuration examples.
[0078] Users can input commands and information into computing device 800 using input devices such as keyboard 838 and pointer device 840. Other input devices (not shown) may include microphone, joystick, gamepad, satellite dish, scanner, touchscreen and / or touchpad, voice recognition system for receiving voice input, gesture recognition system for receiving gesture input, etc. These and other input devices are typically connected to processor circuitry 802 via serial port interface 842 coupled to bus 806, but may be connected via other interfaces such as parallel port, game port, or universal serial bus (USB).
[0079] Display screen 844 is also connected to bus 806 via an interface (e.g., video adapter 846). Display screen 844 may be located externally to computing device 800 or integrated within computing device 800. Display screen 845 may display information or serve as a user interface for receiving user commands and / or other information (e.g., via touch, finger gestures, virtual keyboard, etc.). In addition to display screen 844, computing device 800 may also include other peripheral output devices (not shown), such as speakers and printers.
[0080] Computing device 800 is connected to network 848 (e.g., the Internet) via an adapter or network interface 850, modem 852, or other means of establishing communication over a network. Figure 8 As shown, the modem 852 can be internal or external, and can be connected to the bus 806 via the serial port interface 842, or connected to the bus 80 using other interface types (including parallel interfaces).
[0081] As used herein, the terms “computer program medium,” “computer-readable medium,” and “computer-readable storage medium” generally refer to physical hardware media, such as a hard disk associated with hard disk drive 814, removable disk 818, removable optical disk 822, other physical hardware media (e.g., RAM, ROM, flash memory cards, digital video disks, zip disks, MEM, nanotechnology-based storage devices), and other types of physical / tangible hardware storage media (including…). Figure 8 The system memory (804). This type of computer-readable storage medium is distinct from and does not overlap with (excluding) communication media. Communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals (such as carrier waves). The term "modulated data signal" refers to a signal having one or more characteristics that are set or altered in a way that can encode information in the signal. For example, but not limited to, communication media include wireless media such as acoustic, RF, infrared, and other wireless media, as well as wired media. The embodiments also pertain to such communication media.
[0082] As described above, computer programs and modules (including application program 832 and other programs 834) can be stored on a hard disk, magnetic disk, optical disk, ROM, RAM, or other hardware storage medium. Such computer programs can also be received via network interface 850, serial port interface 852, or any other interface type. When an application executes or loads these computer programs, it enables the computing device 800 to implement the features of the embodiments discussed herein. Therefore, these computer programs represent the controller of the computing device 800.
[0083] The embodiments also relate to computer program products containing computer code or instructions stored on any computer-readable medium. Such computer program products include hard disk drives, optical disk drives, storage device packages, memory sticks, memory cards, and other types of physical storage hardware.
[0084] IV. Other Exemplary Examples This paper describes a method implemented by a computing device. The method includes: receiving multiple configuration settings of the computing device from a server via a network; applying a first subset of the configuration settings from the multiple configuration settings to a host operating system running on the computing device; storing the configuration settings in a local data store; retrieving at least a second subset of the configuration of the multiple configuration settings from the local data store via a containerized application instantiated by the host operating system and running on the computing device; and applying the second subset of the configuration settings from the multiple configuration settings to the containerized application.
[0085] In an embodiment of the method, the method further includes: applying a first filtering rule to a plurality of configuration settings to determine a first subset of the configuration settings, the first subset of the configuration settings being applicable to a host operating system; and applying a second filtering rule to a plurality of configuration settings to determine a second subset of the configuration settings, the second subset of the configuration settings being applicable to containerized applications.
[0086] In an embodiment of the method, the host operating system receives the first and second filtering rules from a filtering rule service via a network.
[0087] In an embodiment of the method, the method further includes: the containerized application providing a request for additional configuration settings to the host operating system; the host operating system forwarding the request to a server via a network; the host operating system receiving the additional configuration settings from the server via a network; storing the additional configuration settings in a local data store; and the containerized application retrieving other configuration settings from the local data store.
[0088] In an embodiment of the method, the method further includes: storing a first result of the application of a first subset of the configuration settings in a local data storage, the first result indicating whether the application of the first subset of the configuration settings is successful; storing a second result of the application of a second subset of the configuration settings in a local data storage, the second result indicating whether the application of the second subset of the configuration settings is successful; merging the first result and the second result to generate a merged result; and providing the merged result to a server via a network.
[0089] In an embodiment of the method, the method further includes: receiving additional configuration settings from a server via a network based on the merging result.
[0090] In embodiments of the method, the multiple configuration settings include at least one of the following: security settings to be implemented for the computing device; network settings to be implemented for the computing device; encryption settings to be implemented for the computing device; or application behavior settings to be implemented for containerized applications.
[0091] This document also describes a computing device. The computing device includes at least one processor circuitry and at least one memory storing program code configured to be executed by the at least one microprocessor circuitry. The program code includes: a first configuration agent of a host operating system installed on the computing device, the first configuration agent being configured to: receive multiple configuration settings for the computing device from a server via a network; apply a first subset of the configuration settings from the multiple configuration settings to the host operating system executing on the computing device; and store the configuration settings in a local data storage; and a second configuration agent of a containerized application instantiated by the host operating system, the second configuration agent being configured to: retrieve at least a second subset of the configuration settings from the multiple configuration settings; and apply the second subset of the configuration settings from the multiple configuration settings to the containerized application.
[0092] In an embodiment of the computing device, a first configuration agent is configured to apply a first filtering rule to multiple configuration settings to determine a first subset of the configuration settings applicable to the host operating system; and a second configuration agent is configured to apply a second filtering rule to multiple configuration settings to determine a second subset of the configuration settings applicable to containerized applications.
[0093] In an embodiment of the computing device, the host operating system is configured to receive a first filtering rule and a second filtering rule from a filtering rule service via a network.
[0094] In an embodiment of the computing device, the second configuration agent is further configured to: provide a request for additional configuration settings to the host operating system; and the first configuration agent is further configured to: forward the request to the server via a network; receive the additional configuration settings from the server via a network; and store the additional configuration settings in a local data storage, and the second configuration agent is further configured to apply the additional configuration settings to a containerized application.
[0095] In an embodiment of the computing device, the first configuration agent is further configured to: store a first result of the application of a first subset of the configuration settings in a local data storage, the first result indicating whether the application of the first subset of the configuration settings is successful; the second configuration agent is further configured to: store a second result of the application of a second subset of the configuration settings in a local data storage, the second result indicating whether the application of the second subset of the configuration settings is successful; and the program code further includes: a result merger configured to: merge the first result and the second result to generate a merged result; and provide the merged result to the first configuration agent, the first configuration agent being further configured to prove the merged result to a server via a network.
[0096] In an embodiment of the computing device, the first configuration agent is further configured to receive additional configuration settings from the server via the network based on the merged result.
[0097] In embodiments of the computing device, the multiple configuration settings include at least one of the following: security settings to be implemented for the computing device; network settings to be implemented for the computing device; encryption settings to be implemented for the computing device; or application behavior settings to be implemented for containerized applications.
[0098] This document also describes a computer-readable storage medium having program instructions recorded thereon, which, when executed by at least one processor, perform a method. The method includes: receiving a plurality of configuration settings for a computing device from a server via a network; applying a first subset of the configuration settings from the plurality of configuration settings to a host operating system executing on the computing device; storing the configuration settings in a local data storage; retrieving at least a second subset of the configuration settings from the local data storage via a containerized application instantiated by the host operating system and executing on the computing device; and applying the second subset of the configuration settings from the plurality of configuration settings to the containerized application.
[0099] In an embodiment using a computer-readable storage medium, the method further includes: applying a first filtering rule to a plurality of configuration settings to determine a first subset of the configuration settings applicable to a host operating system; and applying a second filtering rule to the plurality of configuration settings to determine a second subset of the configuration settings applicable to a containerized application.
[0100] In an embodiment using a computer-readable storage medium, the host operating system receives the first and second filtering rules from a filtering rules service via a network.
[0101] In an embodiment using a computer-readable storage medium, the method further includes: providing a request for additional configuration settings to a host operating system by a containerized application; forwarding the request to a server via a network by the host operating system; receiving the additional configuration settings from the server via a network by the host operating system; storing the additional configuration settings in a local data storage; and retrieving other configuration settings from the local data storage by the containerized application.
[0102] In an embodiment using a computer-readable storage medium, the method further includes: storing a first result of the application of a first subset of the configuration settings in a local data storage, the first result indicating whether the application of the first subset of the configuration settings is successful; storing a second result of the application of a second subset of the configuration settings in the local data storage, the second result indicating whether the application of the second subset of the configuration settings is successful; merging the first result and the second result to generate a merged result; and providing the merged result to a server via a network.
[0103] In an embodiment using a computer-readable storage medium, the method further includes receiving additional configuration settings from a server via a network based on the merging result.
[0104] V. Conclusion While various embodiments have been described above, it should be understood that they are presented by way of example only and not as limitations. It will be apparent to those skilled in the art that various changes in form and detail can be made to them without departing from the spirit and scope of the embodiments of the invention. Therefore, the breadth and scope of these embodiments should not be limited to any of the exemplary embodiments described above, but should be defined solely by the following claims and their equivalents.
Claims
1. A method implemented by a computing device, comprising: Receive multiple configuration settings for the computing device from a server via a network; The computing device determines a first subset of configuration settings by applying a first filtering rule to the plurality of configuration settings, the first filtering rule being stored in the local data storage of the host operating system of the computing device; Apply the first subset of configuration settings to the host operating system; The multiple configuration settings are stored in the local data storage of the host operating system; In response to the containerized application being instantiated by the host operating system on the computing device: The containerized application retrieves the multiple configuration settings from the local data storage of the host operating system; The containerized application determines at least one second subset of the configuration settings by applying a second filtering rule to the plurality of configuration settings, the second filtering rule being stored in the containerized application's local data storage, and the second subset of the configuration settings being different from the first subset of the configuration settings; as well as The containerized application applies the second subset of configuration settings to the containerized application.
2. The method according to claim 1, wherein the first filtering rule and the second filtering rule are received by the host operating system from the filtering rule service via the network.
3. The method according to claim 1, further comprising: The containerized application provides a request for additional configuration settings to the host operating system; The host operating system forwards the request to the server via the network; The additional configuration settings are received by the host operating system from the server via the network; The additional configuration settings are stored in the local data storage of the host operating system; as well as The containerized application retrieves the additional configuration settings from the local data storage of the host operating system.
4. The method according to claim 1, further comprising: The first result of the application of the first subset of configuration settings is stored in the local data storage of the host operating system, and the first result indicates whether the application of the first subset of configuration settings is successful; The second result of the application of the second subset of the configuration settings is stored in the local data storage of the host operating system, and the second result indicates whether the application of the second subset of the configuration settings is successful; The first result and the second result are combined to generate a merged result; as well as The merged result is provided to the server via the network.
5. The method according to claim 4, further comprising: Based on the merged result, additional configuration settings are received from the server via the network.
6. The method of claim 1, wherein the plurality of configuration settings include at least one of the following: Security settings to be implemented for the aforementioned computing device; Network settings to be implemented for the aforementioned computing device; Encryption settings to be implemented for the computing device; or Application behavior settings need to be configured for the containerized application.
7. A computer-readable storage medium having program instructions recorded thereon, the program instructions executing a method when executed by at least one processor of a computing device, the method comprising: Receive multiple configuration settings for the computing device from a server via a network; The computing device determines a first subset of configuration settings by applying a first filtering rule to the plurality of configuration settings, the first filtering rule being stored in the local data storage of the host operating system of the computing device; Apply the first subset of configuration settings to the host operating system; The multiple configuration settings are stored in the local data storage of the host operating system; In response to the containerized application being instantiated by the host operating system on the computing device, The containerized application retrieves the multiple configuration settings from the local data storage of the host operating system; The containerized application determines at least one second subset of the configuration settings by applying a second filtering rule to the plurality of configuration settings, the second filtering rule being stored in the containerized application's local data storage, and the second subset of the configuration settings being different from the first subset of the configuration settings; as well as The containerized application applies the second subset of configuration settings to the containerized application.
8. The computer-readable storage medium of claim 7, wherein the second subset of the configuration is specific to the containerized application.
9. The computer-readable storage medium of claim 8, wherein the first filtering rule and the second filtering rule are received by the host operating system from a filtering rule service via the network.
10. The computer-readable storage medium of claim 7, further comprising: The containerized application provides a request for additional configuration settings to the host operating system; The host operating system forwards the request to the server via the network; The additional configuration settings are received by the host operating system from the server via the network; The additional configuration settings are stored in the local data storage of the host operating system; as well as The containerized application retrieves the additional configuration settings from the local data storage of the host operating system.
11. The computer-readable storage medium of claim 7, further comprising: The first result of the application of the first subset of configuration settings is stored in the local data storage of the host operating system, and the first result indicates whether the application of the first subset of configuration settings is successful; The second result of the application of the second subset of the configuration settings is stored in the local data storage of the host operating system, and the second result indicates whether the application of the second subset of the configuration settings is successful; The first result and the second result are combined to generate a merged result; as well as The merged result is provided to the server via the network.
12. The computer-readable storage medium of claim 11, further comprising: Based on the merged result, additional configuration settings are received from the server via the network.
13. The computer-readable storage medium of claim 7, wherein the containerized application stores the plurality of configuration settings in the local data storage of the containerized application.
14. A computing device, comprising: At least one processor circuit; as well as At least one memory storing program code configured to be executed by the at least one processor circuit, the program code comprising: A first configuration agent for the host operating system installed on the computing device, the first configuration agent being configured as follows: Receive multiple configuration settings for the computing device from a server via a network; The computing device determines a first subset of configuration settings by applying a first filtering rule to the plurality of configuration settings, the first filtering rule being stored in the local data storage of the host operating system; Apply the first subset of the configuration settings to the host operating system; and The plurality of configuration settings are stored in the local data storage of the host operating system; and A second configuration agent for the containerized application instantiated by the host operating system, the second configuration agent being configured as follows: In response to the instantiation of the containerized application, the plurality of configuration settings are retrieved from the local data storage of the host operating system; By applying a second filtering rule to the plurality of configuration settings, at least one second subset of the configuration settings is determined. The second filtering rule is stored in the local data storage of the containerized application, and the second subset of the configuration settings differs from the first subset of the configuration settings. Apply the second subset of the configuration settings to the containerized application.
15. The computing device of claim 14, wherein the second subset configured is specific to the containerized application.
16. The computing device of claim 15, wherein the host operating system is configured to receive the first filtering rule and the second filtering rule from a filtering rule service via the network.
17. The computing device of claim 14, wherein the second configuration agent is further configured to: Provide the host operating system with a request for additional configuration settings; and The first configuration agent is further configured as follows: The request is forwarded to the server via the network; Receive the additional configuration settings from the server via the network; as well as The additional configuration settings are stored in the local data storage of the host operating system, and the second configuration agent is further configured to apply the additional configuration settings to the containerized application.
18. The computing device of claim 14, wherein the first configuration agent is further configured to: The first result of the application of the first subset of configuration settings is stored in the local data storage of the host operating system, and the first result indicates whether the application of the first subset of configuration settings is successful; The second configuration agent is further configured as follows: The second result of the application of the second subset of the configuration settings is stored in the local data storage of the host operating system, and the second result indicates whether the application of the second subset of the configuration settings is successful; as well as The program code also includes: The result merger is configured as follows: The first result and the second result are combined to generate a merged result; as well as The merge result is provided to the first configuration agent, which is also configured to prove the merge result to the server via the network.
19. The computing device of claim 18, wherein the first configuration agent is further configured to: Based on the merged result, additional configuration settings are received from the server via the network.
20. The computing device of claim 14, wherein the plurality of configuration settings include at least one of the following: Security settings to be implemented for the aforementioned computing device; Network settings to be implemented for the aforementioned computing device; Encryption settings to be implemented for the computing device; or Application behavior settings need to be configured for the containerized application.
Citation Information
Patent Citations
Network virtualization of containers in computing systems
CN108780410A
Automatic domain join for virtual machine instances
US10509663B1