Streamlined secure deployment of cloud services

By introducing deployment resource providers (DRP) and automated deployment processes, the problem of difficulty for private cloud providers to deploy cloud services is solved, and streamlined security deployment and user experience of cloud services are achieved.

CN119988029APending Publication Date: 2025-05-13MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510130229.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2019-03-01
Filing Date
2019-11-22
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Due to differences in resources or capabilities, private cloud providers find it difficult to effectively deploy or update cloud services, resulting in a reduced user experience.

Method used

Introduce deployment resource providers (DRPs) to automate the deployment process of cloud services by creating special deployment subscriptions and initial resource sets, without even accessing cloud services.

Benefits of technology

It realizes streamlined and secure deployment of cloud services, simplifies the deployment process, reduces dependence on the development team, and improves the user experience of the private cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119988029A_ABST
    Figure CN119988029A_ABST
Patent Text Reader

Abstract

Techniques for streamlined secure deployment of cloud services in a cloud computing environment are disclosed herein. In one embodiment, a method may include, in response to receiving an instruction to deploy a cloud service in a cloud computing system, creating a deployment subscription for a resource in the cloud computing system, the deployment subscription being owned by the deployment service; and instantiating one or more computing resources accessible by a deployment service in the cloud computing system according to the created deployment subscription. The method further includes retrieving one or more components of an application corresponding to the cloud service based on the manifest having the instantiated one or more computing resources; and installing the one or more components of the retrieved application in the cloud computing system according to the installation order identified in the list.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with international application number PCT / US2019 / 062710, application date November 22, 2019, application number 201980076930.6, and invention name “Streamlined Secure Deployment of Cloud Services”. Background Art

[0002] Remote or "cloud" computing typically utilizes a collection of remote servers to provide computing, data storage, electronic communications, or other cloud services. A computer network can interconnect remote servers to form a computing structure with one or more computing clusters. During operation, multiple servers in the computing structure can collaborate to provide a distributed computing environment that supports the execution of user applications in order to provide the desired cloud services. Summary of the invention

[0003] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0004] A cloud computing system may include a large number of remote servers or nodes configured to provide various cloud computing services via a computer network. A cloud computing system or "cloud" may be public or private, depending on access restrictions. For example, a public cloud provides subscriptions to cloud services to the general public, while a private cloud is accessible only to an organization's users due to security, data protection, privacy, or other considerations. Examples of public clouds include Microsoft Azure, Microsoft Azure, and Microsoft Azure. Amazon Web and Google On the other hand, companies, universities, government entities and other organizations can often configure dedicated servers, data centers or other computing facilities to deploy cloud services for internal use only. Such cloud computing systems are often referred to as private clouds.

[0005] Public cloud and private cloud computing systems can provide different resources, resource capabilities, features or other operating characteristics to each other. Due to changes in the deployment version of the cloud platform, cloud applications, service type provision, available resource content or resource attribute capabilities, the aforementioned differences can usually be dynamic. For example, compared with public clouds, private clouds usually operate in a restricted infrastructure topology. Therefore, private clouds usually provide fewer infrastructure fault domains or other computing capabilities. In another example, private clouds usually do not provide a variety of infrastructure types, such as server types, storage capabilities, etc. Therefore, resource attribute capabilities (such as deployable virtual machine types in private cloud servers) may be limited. In another example, a private cloud can provide a subset of the available application programming interface ("API") versions available in a public cloud. In another example, a specific version of a private cloud can have a different set of available resources compared to the resources provided in the public cloud and can be provided in a later version of the private cloud.

[0006] The differences between public and private clouds may result in the deployment of new / updated cloud applications / services requiring different deployment processes, which private cloud providers may not easily adapt to. For example, public cloud providers (e.g., Amazon.com) typically have a team of developers that develop applications and associated components corresponding to cloud services. During deployment, the development team can support the deployment of cloud services by using deployment scripts to identify, install, debug, and / or perform other appropriate actions on the various application components of the cloud services. Therefore, with the support of the development team, this deployment process can operate satisfactorily.

[0007] However, when a private cloud provider attempts to deploy or update the same cloud service due to various resource or capability differences, the aforementioned deployment process for the public cloud may not operate satisfactorily. Typically, a private cloud provider does not have a development team dedicated to cloud services, nor does the private cloud provider have access to the development team from the public cloud provider. Therefore, a complex deployment process involving adjusting deployment scripts, etc., often prevents private cloud providers from deploying new cloud services. As a result, the user experience of the private cloud may be degraded.

[0008] Several embodiments of the disclosed technology relate to streamlined secure deployment of cloud services in a cloud computing system, even without access to the development team of the cloud service. In certain implementations, the disclosed technology can provide an "appliance experience" whereby internal components associated with the deployed cloud service are kept internal and invisible to the cloud service provider. Thus, the implementation of the cloud service (resources, such as a hypervisor for managing virtual machines, a storage hardware service for allocating user storage accounts, or a domain controller for managing internal service identities, etc.) is considered an internal component or "guts" and is kept internal and not exposed to the cloud service provider.

[0009] In one example implementation, a deployment service or deployment resource provider (DRP) is provided in a cloud computing system (e.g., a public cloud or a private cloud) for deploying, updating, troubleshooting, and / or otherwise managing resources in the cloud computing system. When a new cloud service (or an update to an existing cloud service) is deposited to the DRP (e.g., from a public cloud), a deployment manifest for the new cloud service is provided to guide the DRP when deploying or updating the new cloud service. The deployment manifest may include data representing a list of application components, a list of application component updates, an installation order, a configuration profile for the application components, and other suitable information about the installation of the application components. The deployment manifest may be in any suitable file format, such as JavaScript Object Notation (JSON).

[0010] When activated, the DRP performs a "bootstrapping" operation by creating a new special subscription (referred to herein as a "deployment subscription") in the cloud computing system where the new cloud service is to be deployed. Depending on the deployment manifest, the deployment subscription can adopt a "consumption" or "metered" billing model. Unlike typical subscriptions owned by actual users or administrators of the cloud computing system, the deployment subscription is owned by the DRP and is invisible to any actual users or administrators of the cloud computing system. This invisibility allows the deployment subscription to remain hidden from the user while providing the ability to deploy and run new cloud services internally.

[0011] Once a deployment subscription is created in a cloud computing system, the DRP can create an initial set of resources used to support the deployment process based on the deployment manifest. For example, the initial set of resources may include a key vault or other suitable secret storage device suitable for storing credentials, virtual machines, containers (e.g., Docker containers), storage accounts, etc., which is configured to collect user-provided input (e.g., secrets, such as passwords, etc.) for cloud service deployment. Typically, the input data provided by the user may include parameters such as security credentials that allow cloud services to operate in the cloud computing system. In some implementations, the initial set of resources may have metadata that describes the exact requirements (e.g., the type of security credentials, etc.) that can be used to store and verify user-provided values. Another pre-deployment operation may include collecting the remaining non-secret parameters, such as user preferences, etc.

[0012] After all inputs are collected, the DRP can begin the deployment process. Unlike a typical deployment by a development team, in which team members know the exact details of the (multiple) deployment scripts and have direct access to the computing environment (e.g., for troubleshooting purposes), the DRP can be configured to perform the deployment, rather than users or administrators of the cloud computing system. In one example, a user instructs the DRP to deploy a cloud service, and in response, the DRP retrieves the (multiple) resource manager templates specified in the deployment manifest (which are signed and hidden from the user), retrieves the appropriate components or component updates based on the resource manager templates (e.g., from a public cloud), and deploys the retrieved components or component updates. The DRP can be configured to perform multiple operations of a complex deployment, including creating and deleting resources, calling endpoints (e.g., virtual machines), etc. In order to add new cloud services and "extend" the cloud computing system, an API set (e.g., *.provider namespace) can be implemented in the cloud computing system. Therefore, exposing users to the "innards" of the deployed cloud services can be avoided. Users can also be prevented from interfering with content involved during the deployment of cloud services because users cannot access such content.

[0013] Another aspect of the disclosed technology relates to managing secrets required to provide certain cloud services in a cloud computing system. Typically, secrets are stored in a secure location (e.g., a key vault or other suitable type of secret storage device) where cloud services can access the stored secrets. However, this approach may have multiple disadvantages. For example, giving cloud service providers (e.g., administrators) direct access to the secure location where secrets are stored can create opportunities for cloud service providers to mistakenly modify or "fat-finger" one or more stored secrets. Cloud service providers may also inadvertently supply invalid secrets (wrong domain, wrong credential type, etc.) to the secure location. Moreover, some secrets have both public and private parts (e.g., public and private keys) and need to be updated in a consistent manner. Any of the aforementioned problems may render the cloud service inoperable and is unacceptable for "device" style operations that deploy cloud services. To address at least some aspects of this problem, a DRP can be configured to provide indirection between cloud service providers (humans) and cloud services that consume secrets. The DRP ensures that secrets are valid and updated appropriately for public and private parts.

[0014] According to an embodiment of the disclosed technology, when a cloud service is deployed in a cloud computing system, the aforementioned deployment / update process can implement a device experience. Instead of a human operator, the DRP can be configured to handle operations such as creating one or more subscriptions, creating / updating / deleting resources, calling endpoints in the cloud computing system, executing custom scripts, sending various telemetry and summaries about the deployment process and results. The deployment parameters provided by the user during the deployment / update process can be cached or otherwise remembered to avoid requesting the same input during (multiple) subsequent updates, thereby eliminating or at least reducing the risk of inconsistent values ​​provided by the user. Secret management can be configured to allow the cloud service provider to view all secrets in the computing system, corresponding attributes (such as key length, creation / expiration date, etc.), and rotate them appropriately individually or all at once or between the two. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 is a schematic diagram of a hybrid cloud computing system according to an embodiment of the disclosed technology.

[0016] Figure 2A is a diagram illustrating an embodiment of the disclosed technology suitable for Figure 1 Schematic diagram of a cloud computing system in a hybrid cloud computing system.

[0017] Figure 2B is a diagram illustrating an embodiment according to the disclosed technology Figure 2A Schematic diagram of some hardware / software components of a cloud computing system.

[0018] FIG. 3A to FIG. 3D is a diagram illustrating a process during certain stages of a streamlined secure deployment of a cloud service according to an embodiment of the disclosed technology. Figure 1 A schematic diagram of some of the hardware / software components of a cloud computing environment.

[0019] Figure 4 is a diagram illustrating an embodiment according to the disclosed technology Figures 3A to 3D A diagram of some of the hardware / software components of a deployment resource provider in .

[0020] FIG. 5A to FIG. 5C is a flow chart illustrating various aspects of a process for streamlined secure deployment of cloud services according to an embodiment of the disclosed technology.

[0021] Figure 6 Is suitable for Figure 1 Computing devices that are certain components of a cloud computing environment. DETAILED DESCRIPTION

[0022] Certain embodiments of computing systems, devices, components, modules, routines, and processes for supporting streamlined secure deployment of cloud services are described below. In the following description, specific details of the components are included to provide a thorough understanding of certain embodiments of the disclosed technology. Those skilled in the relevant art will also understand that the disclosed technology may have additional embodiments or may be used without the following references. Figures 1 to 6 The described embodiments are practiced without departing from the scope of the invention.

[0023] As used herein, the term "cloud computing system" or "cloud" generally refers to a computer system configured to provide various cloud computing services via a computer network. A cloud computing system may include multiple network devices that interconnect a large number of remote servers or nodes to each other and / or to an external network (e.g., the Internet). In one example, a cloud computing system may include multiple containers, racks, or other suitable enclosures that hold multiple servers in a cloud computing data center (or portions thereof), respectively. The term "network device" generally refers to a network communication component. Example network devices include routers, switches, hubs, bridges, load balancers, security gateways, or firewalls. A "node" generally refers to a computing device configured to implement one or more virtual machines, virtual routers, virtual gateways, or other suitable virtualized computing components. For example, a node may include a computing server with a hypervisor that is configured to support one or more virtual machines.

[0024] As used herein, the term "public cloud" or "public cloud computing system" generally refers to a cloud computing system that provides cloud service subscriptions to the public. Examples of public clouds include Microsoft Amazon Web and Google The term "subscription" generally refers to a definition of the scope of (multiple) cloud services or cloud resources provided by a cloud service provider to a user. In contrast, the term "private cloud" or "private cloud computing system" generally refers to a cloud computing system that is used internally by an organization and is under the organization's strict access control due to security, data protection, privacy or other issues. Public clouds or users outside the organization generally cannot access the organization's private cloud. The term "hybrid cloud" generally refers to a cloud computing system in which one part is a first cloud (e.g., a public cloud) interconnected with another part that is a second cloud (e.g., a private cloud). As discussed in more detail below, multiple embodiments of the disclosed technology can support streamlined and secure deployment of cloud services in public, private, and hybrid clouds.

[0025] As also used herein, the term "cloud computing service" or "cloud service" generally refers to one or more computing resources provided over a computer network, such as the Internet. Example cloud services include software as a service ("SaaS"), platform as a service ("PaaS"), and infrastructure as a service ("IaaS"). SaaS is a software distribution technology in which software applications are hosted by a cloud service provider, such as in a data center, and accessed by users over a computer network. PaaS generally refers to the delivery of an operating system and associated services over a computer network without the need for downloading or installing. IaaS generally refers to outsourced equipment used to support storage devices, hardware, servers, network equipment, or other components, all of which are accessible over a computer network.

[0026] As also used herein, the term "resource provider" generally refers to a cloud service that is configured to provide or make available one or more cloud services or resources of a public cloud or private cloud. Resources can be deployed and managed by, for example, a "resource manager" accessible via a user portal. In certain embodiments, a resource provider may be configured to provide a representational state transfer ("REST") application programming interface ("API") to work with associated resources. For example, a resource provider may be configured to deploy a secret storage device (e.g., a key vault) for storing keys and credentials. The resource provider may provide an example resource type called "vault" to create a key vault and another example resource type called "vault / secret" to create a secret in a key vault. In other embodiments, a resource provider may also provide computing resources (e.g., virtual machines), storage resources (e.g., network storage devices), network resources (e.g., virtual networks), database resources (e.g., database servers), or other suitable types of resources.

[0027] Different cloud computing systems may provide different resources and / or capabilities to users of cloud services provided by the cloud computing systems. For some cloud computing systems, such as private clouds, it may be difficult to deploy new or updated cloud services due to the nature of the resources and / or capabilities available at the cloud computing system, which results in a certain degree of deployment customization. As such, some cloud service providers (e.g., private cloud providers) may be dissuaded from deploying new / updated cloud services in the corresponding cloud computing system. The lack of availability of new / updated cloud services may have a negative impact on user experience, security, privacy protection, or other suitable features of the cloud computing system.

[0028] Multiple embodiments of the disclosed technology can address at least some of the aforementioned shortcomings by enabling streamlined, secure deployment of cloud services in a cloud computing system. In certain implementations, the disclosed technology can provide a "device experience" whereby internal components associated with a deployed cloud service are kept internal and invisible to the cloud service provider. Therefore, the implementation of the cloud service (resources, such as a hypervisor for managing virtual machines, a storage hardware service for allocating user storage accounts, or a domain controller for managing internal service identities, etc.) are considered internal components or "guts" and are kept internal and not exposed to the cloud service provider. Therefore, as described below with reference to Figures 1 to 6 As described in more detail, at least complex deployment customization can be reduced, if not eliminated.

[0029] Figure 1 1 is a schematic diagram illustrating a cloud computing environment 100 for implementing secure deployment of cloud services according to an embodiment of the disclosed technology. Figure 1 As shown, cloud computing environment 100 may include one or more public clouds 108 and private clouds 106 interconnected with client devices 102 associated with user 101 via computer network 104. Computer network 104 may include an intranet, a wide area network, a local area network, the Internet, or other suitable types of networks. An example of computer network 104 is shown below with reference to Figure 2A Described in more detail.

[0030] Even though the specific components and associated arrangements of the cloud computing environment 100 are Figure 1, but in other embodiments, the cloud computing environment 100 may include additional and / or different components. For example, in the illustrated embodiment, the cloud computing environment 100 includes two (i.e., first and second) private clouds 106a and 106b and two (i.e., first and second) public clouds 108a and 108b. In other embodiments, the cloud computing environment 100 may include three, four, or any other suitable number of private clouds 106 and / or public clouds 108. In other embodiments, the cloud computing environment 100 may include only a public cloud 108 without a private cloud 106, or vice versa. In other embodiments, the cloud computing environment 100 may also include a web server, a domain name server, or other suitable components.

[0031] The client device 102 may solely comprise a computing device that enables the user 101 to access the public cloud 108 and / or the private cloud 106 via the computer network 104. For example, in the illustrative embodiment, the client device 102 solely comprises a desktop computer. In other embodiments, the client device 102 may also comprise a laptop computer, a tablet computer, a smartphone, or other suitable computing device. Even though for illustration purposes three users 101 are connected to the public cloud 108 and / or the private cloud 106, the client device 102 may be configured to communicate with the user 101 via the computer network 104. Figure 1 , but in other embodiments, cloud computing environment 100 may support access to public cloud 108 and / or private cloud 106 by any suitable number of users 101 via computer network 104.

[0032] The public cloud 108 and the private cloud 106 may be individually configured to provide subscriptions to certain cloud services to the user 101. Figure 1 As shown, the public cloud 108 is open to the public. Therefore, all users 101 can access the public cloud 108. On the other hand, the private cloud 106 can have strict access control. Therefore, only authorized users 101 can access the private cloud 106. For example, the first user 101a and the second user 101b can be authorized to access the first private cloud 106a and the second private cloud 106b respectively, but cannot access the third user 101c. Therefore, the third user 101c has no right to access the first private cloud 106a or the second private cloud 106b, but only has the right to access the public clouds 108a and 108b. The cloud computing system 110 (such as the one suitable for the public cloud 108 or the private cloud 106) Figure 2A The example components shown below are referenced FIG. 2A to FIG. 2B Described in more detail.

[0033] like Figure 1As shown, each of the private cloud 106 and the public cloud 108 may have different resources, capabilities, or functionality. For example, the first private cloud 106a may have an earlier version of the cloud platform than the second cloud 106b. In another example, the private cloud 106 may have limited capabilities and / or features when compared to the first public cloud 108a or the second public cloud 108b. In yet another example, the first public cloud 108a and the second public cloud 108b may also have different capabilities or functionality. This difference may create challenges when a cloud provider (not shown), a user 101 of the first private cloud 106a and the second private cloud 106b, deploys new / updated cloud applications / services in the first private cloud 106a and the second private cloud 106b. As described below with reference to FIG. 3A to FIG. 3D As described in more detail, various embodiments of the disclosed technology can enable secure, streamlined deployment of cloud services to allow a “device experience” for deploying new / updated cloud services in, for example, the first private cloud 106a and the second private cloud 106b tiers.

[0034] Figure 2A is a diagram illustrating an embodiment of the disclosed technology suitable for Figure 1 Schematic diagram of a cloud computing system 110 of a public cloud 108 or a private cloud 106. Figure 2A As shown, cloud computing system 110 may include an underlying network 109 interconnecting a plurality of client devices 102 associated with users 101 and computing structures 114. Although specific components of cloud computing system 110 are described in detail below, Figure 2A , but in other embodiments, the cloud computing system 110 may also include additional and / or different components. For example, the cloud computing system 110 may also include additional computing structures (not shown) interconnected with each other, network storage devices, utility infrastructure, and / or other suitable components.

[0035] like Figure 2A As shown, the underlying network 109 may include one or more physical network devices 113 that interconnect the users 101 and the computing structures 114. Examples of network devices 113 may include routers, switches, firewalls, load balancers, or other suitable network components. Even though specific connection schemes are not described for illustration purposes, Figure 2A , but in other embodiments, the network devices 113 may be operably coupled in a hierarchical, flat, "mesh," or other suitable topology.

[0036] like Figure 2AAs shown, the computing structure 114 may include multiple nodes 105 that are operably coupled to each other through a network device 113. In some embodiments, the node 105 may individually include a processor, a physical server, or multiple physical servers. In other embodiments, the node 105 may also include a virtual server or multiple virtual servers. The nodes 105 can be organized into racks, availability zones, groups, sets, computing clusters, or other suitable partitions. For example, in the illustrated embodiment, the nodes 105 are grouped into three computing clusters 107 (individually shown as a first computing cluster 107a, a second computing cluster 107b, and a third computing cluster 107c), which are operably coupled to corresponding network devices 113 in the underlying network 109. Although for illustrative purposes the three computing clusters 107 are shown in Figure 2A 1 , but in other embodiments, computing structure 114 may include one, two, eight, sixteen, or any other suitable number of computing clusters 107 (having similar or different components and / or configurations).

[0037] like Figure 2A As shown, the computing structure 114 may also include a management controller 115 configured to monitor, control or otherwise manage the operation of the nodes 105 in the computing cluster 107. For example, in some embodiments, the management controller 115 may include a fabric controller configured to manage processing, storage, communication or other suitable types of hardware resources in the computing cluster 107 for hosting cloud services. In other embodiments, the management controller 115 may also include a data center controller, an application delivery controller, or other suitable types of controllers. In the illustrated embodiment, the management controller 115 is shown as being separate from the computing cluster 107. In other embodiments, the management controller 115 may include one or more nodes 105 in the computing cluster 107. In other embodiments, the management controller 115 may include software services hosted on one or more nodes 105 in the computing cluster 107.

[0038] In operation, user 101 may request deployment of a cloud service via, for example, a user portal (not shown). For example, user 101 may request instantiation of virtual machine 145 (e.g., Figure 2B In response to receiving the request from user 101, management controller 115 may verify the subscription level of user 101 and provision the instantiation of the virtual machine upon verification. Management controller 115 may then cause one or more of nodes 105 to instantiate the requested virtual machine 145, as described below with reference to Figure 2B Described in more detail.

[0039] Figure 2B is a diagram illustrating an embodiment of the disclosed technology implemented on the underlying network 109 and suitable for Figure 2AA schematic diagram of an example underlying network 109' of a cloud computing system 110. Figure 2B For the sake of clarity, only Figure 2A Certain components of the underlying network 109 are shown. Figure 2B As shown, the first node 105a and the second node 105b may include a processor 131, a memory 133, and an input / output component 135 operably coupled to each other, respectively. The processor 131 may include a microprocessor, a field programmable gate array, and / or other suitable logic devices. The memory 133 may include volatile and / or non-volatile media (e.g., ROM; RAM, magnetic disk storage media; optical storage media; flash memory devices, and / or other suitable storage media) and / or other types of computer-readable storage media configured to store data received from the processor 131 and instructions for the processor 131. The input / output component 135 may include a display, a touch screen, a keyboard, a mouse, a printer, and / or other suitable types of input / output devices, which are configured to accept input from an operator and / or an automated software controller (not shown) and provide output thereto.

[0040] The memory 133 of the first node 105a and the second node 105b may include instructions executable by the processor 131 to cause each processor 131 to provide a hypervisor 141 (individually identified as a first hypervisor 141a and a second hypervisor 141b) and other suitable components (not shown). The hypervisor 141 may be individually configured to initiate, monitor, terminate and / or otherwise locally manage one or more virtual machines 145 organized as a tenant site 143. For example, Figure 2B As shown, the first node 105a can provide a first hypervisor 141a, which manages a first tenant site 143a and a second tenant site 143b, respectively. The second node 105b can provide a second hypervisor 141b, which manages a first tenant site 143a' and a second tenant site 143b', respectively. The hypervisor 141 can be a software, firmware, or hardware component. The tenant sites 143 can each include multiple virtual machines 145 or other suitable tenant instances of a specific user 101. For example, the first node 105a and the second node 105b can both host the tenant sites 142a and 142a' of the user 101. The first node 105a and the second node 105b can both host the second user 101b ( Figure 1 ) of the tenant sites 143b and 143b'. Each virtual machine 145 can execute a corresponding operating system, middleware and / or application.

[0041] Also like Figure 2BAs shown, the cloud computing system 110 may include an underlying network 109' having one or more virtual networks 147 that interconnect tenant sites 143a and 143b across multiple nodes 105. For example, a first virtual network 147a interconnects first tenant sites 143a and 143a' at a first node 105a and a second node 105b. A second virtual network 147b interconnects second tenant sites 143b and 143b' at a first node 105a and a second node 105b. Even though a single virtual network 147 is shown as corresponding to one tenant site 143, in other embodiments, multiple virtual networks 147 (not shown) may be configured to correspond to a single tenant site 143.

[0042] Even if the virtual machines 145 are located on different nodes 105, the virtual machines 145 on the virtual network 147 can communicate with each other via the underlying network 109 ( Figure 2A ) communicate with each other. The communications of each virtual network 147 in the virtual networks 147 can be isolated from the other virtual networks 147. In some embodiments, communications can be allowed to cross from one virtual network 147 to another virtual network 147 through a security gateway or in a controlled manner. A virtual network address can correspond to one of the virtual machines 145 in a particular virtual network 147. Therefore, different virtual networks 147 can use the same one or more virtual network addresses. Example virtual network addresses can include IP addresses, MAC addresses, and / or other suitable addresses.

[0043] In some embodiments, a virtual machine 145 hosted on one or more nodes 105 may be used to perform one or more user-requested tasks. In other embodiments, a virtual machine 145 or other suitable component of a cloud computing system 110 may also be used to provide services to a public cloud 108 ( Figure 1 ) to implement access services or for each private cloud 106 ( Figure 1 ) to implement the connection service. The access service can be configured to provide information about available resources at the public cloud 108 to the connection service of the private cloud 106. The access service can also be configured to support the private cloud 106 to access the network storage device in the public cloud 108. In some embodiments, for example, by Figure 2A ) in one or more virtual machines 145 on the selected node 105, the access service or the connection service may be implemented separately as a cloud service. In other embodiments, the access service and / or the connection service may be provided by a dedicated server or via other suitable technologies. Figure 2BThe node 105 in the figure is shown as hosting a virtual machine 145 for executing applications to provide suitable cloud services. In other embodiments, the node 105 and / or the virtual machine 145 may also host one or more containers (e.g., Docker containers, not shown), virtual switches, virtual routers and / or other suitable components to execute applications and / or perform other suitable operations to provide corresponding cloud services.

[0044] FIG. 3A to FIG. 3D is a diagram illustrating a process during certain stages of a streamlined secure deployment of a cloud service according to an embodiment of the disclosed technology. Figure 1 A schematic diagram of certain hardware / software components of a cloud computing environment 100 is shown in FIG. FIG. 3A to FIG. 3D In the embodiment of the present invention, some components of the cloud computing environment 100 are omitted for clarity. For example, for illustration purposes, only one private cloud 106 is shown in FIG. FIG. 3A to FIG. 3D Other and / or additional public and / or private clouds may have FIG. 3A to FIG. 3D The components and associated operations shown are similar to those shown.

[0045] Even though the streamlined secure deployment techniques are described below in the context of deploying cloud services from a public cloud 108 to a private cloud 106, in other implementations, the described techniques may also be applied to deploying cloud services from a publishing service to a public cloud, from a public cloud to another public cloud, or from a private cloud to another private cloud. Thus, embodiments of the disclosed techniques are not limited to deploying cloud services from a public cloud to a private cloud.

[0046] In addition, FIG. 3A to FIG. 3D In other figures of this paper, each software component, object, class, module and routine can be a computer program, program or process written as source code in C, C++, C#, Java and / or other suitable programming languages. Components may include, but are not limited to, one or more modules, objects, classes, routines, attributes, processes, threads, executable files, libraries or other components. Components may be in source form or binary form. Components may include various aspects of source code (e.g., classes, attributes, programs, routines) before compilation, compiled binary units (e.g., libraries, executable files) or phantoms (e.g., objects, processes, threads) instantiated and used at runtime. In certain embodiments, the various components and modules described below may be implemented with actors. In other embodiments, the generation of applications and / or related services may also be implemented using monolithic applications, multi-layer applications or other suitable components.

[0047] Components within a system may take different forms within the system. As an example, a system including a first component, a second component, and a third component may encompass, but is not limited to, a system in which the first component is a property of source code, the second component is a binary compiled library, and the third component is a thread created at run time. A computer program, program, or process may be compiled into an object, intermediate, or machine code and presented to be executed by one or more processors in a personal computer, a network server, a laptop, a smart phone, and / or other suitable computing device. Likewise, a component may include a hardware circuit system.

[0048] Those of ordinary skill in the art will recognize that hardware can be viewed as fossilized software, and software can be viewed as liquefied hardware. As just one example, the software instructions in a component can be burned into a programmable logic array circuit, or can be designed as a hardware circuit with an appropriate integrated circuit. Likewise, hardware can be emulated by software. Various implementations of source code, intermediate code, and / or object code and associated data can be stored in a computer memory, which includes a read-only memory, a random access memory, a disk storage medium, an optical storage medium, a flash memory device, and / or other suitable computer-readable storage medium other than a propagating signal.

[0049] like Figure 3A As shown, the public cloud 108 may include a resource manager 122 configured to support management of various resources at the public cloud 108. The public cloud 108 may also include various resource providers 121 configured to provide various resources. For example, in the illustrated embodiment, the public cloud 108 may include an authentication service 124 and a publishing service 126 that are operably coupled to each other. Each of the aforementioned services may be provided via one or more nodes 105 ( Figure 2A ) executes appropriate instructions and the computing structure 114 ( Figure 2A ) cloud services provided by the public cloud 108. The public cloud 108 may also include a repository 111 that contains records of applications 112 that individually correspond to cloud services. The repository 111 may include a database or other suitable network storage device in the public cloud 108. Even if a particular component of the public cloud 108 is Figure 3A As shown in FIG. 1 , in other embodiments, the public cloud 108 may also include storage services, computing services, web services, database services, or other suitable types of resource providers.

[0050] Resource manager 122 may be configured to deploy, monitor, and / or manage services provided to subscribers (eg, Figure 1The resource manager 122 may allow a subscriber to interact with a set of available resources. For example, the resource manager 122 may allow one or more available resources to be deployed, updated, or deleted in a coordinated operation. The resource manager 122 may also be configured to provide security, auditing, and tagging features to support management of resources after deployment. Figure 3A In the embodiment, the resource manager 122 is shown as having a resource manager 122, and in other embodiments, the resource manager 122 may also be omitted. In such embodiments, the subscriber may manage various available resources in the public cloud 108 individually, separately or in other suitable ways.

[0051] The authentication service 124 can be configured to support a variety of authentication and authorization protocols. For example, in some embodiments, the authentication service 124 can be configured to support single-key or multi-key authentication. In other embodiments, the authentication service 124 can also be configured to support key rollover. In other embodiments, the authentication service 124 can also be configured to support granting restricted access to HTTP or other suitable services by coordinating an approval interaction between the user and the service or by allowing the user to obtain restricted access themselves. An example authentication service 124 is provided by Microsoft Corporation of Redmond, Washington. Active Directory Services. In one embodiment, the authentication service 124 may be part of the cloud computing platform of the public cloud 108. In other embodiments, the authentication service 124 may be a standalone service, application, or other suitable component.

[0052] Publishing service 126 may be configured to receive application 112 from, for example, an independent software vendor (ISV) or other suitable source and provide it to user 101 ( Figure 1 ) applications 112. In some embodiments, the ISV may develop a SaaS application and submit the developed SaaS application to the publishing service 126. In turn, the publishing service 126 may be configured to verify the submitted SaaS application to ensure compatibility with the cloud computing platform, the absence of malware or other suitable purposes. The publishing service 126 may also be configured to classify, categorize, or otherwise identify one or more characteristics of the application 112.

[0053] The publishing service 126 can then be configured to store one or more copies of the various components and artifacts of the application 112 in, for example, a repository 111 in the public cloud 108 or other suitable network storage device (not shown). The components of the application 112 may include executable files, libraries, databases, and / or other suitable software modules. As used herein, the term "artifact" generally refers to a by-product produced during software development. For example, use cases, class diagrams, other Unified Modeling Language (UML) models, requirements, design documents, or other suitable types of artifacts can help describe the functionality, architecture, and / or design of the application 112. Other artifacts may contain information related to the development process of the application, such as project plans, business cases, and risk assessments.

[0054] In some embodiments, the publishing service 126 may also publish certain artifacts of the applications 112 to the private cloud 106. For example, in one embodiment, when an ISV submits an application 112, the ISV may elect to have the application 112 also published to the private cloud 106. In response to receiving the submitted application 112, the publishing service 126 may then notify, publish, or otherwise make the private cloud 106 aware of the submitted application 112, such as via an application announcement 150. In other embodiments, all submitted applications 112 may be published to the private cloud 106 by default. In other embodiments, certain categories, classes, groups, or types of applications 112 may be automatically published to the private cloud 106 by default.

[0055] like Figure 3A As shown, the private cloud 106 may include a resource manager 122', a deployment resource provider (shown as "DRP 134"), a computing service 136, and a security service 138 operatively coupled to the repository 111' and the secret storage 114. The resource manager 122' and the repository 111' may be generally similar to the resource manager 122' and the repository 111' of the public cloud 108. For example, the resource manager 122' may be configured to facilitate the administrator 103 to deploy, monitor, and / or manage resources in the private cloud 106 via the client device 102'. The repository 111' may be configured to store records of applications 112' published in the private cloud 106 and other suitable types of data in the private cloud 106.

[0056] The computing service 136 may be configured to provide computing resources to the DRP 134, the users 101, and / or other services of the private cloud 106. For example, in one embodiment, the computing service 136 may be configured to instantiate instances of digital secret storage 114, virtual machines, storage accounts, and / or other suitable types of resources of the DRP 134 to support deployment processes in the private cloud 106, as described in more detail below. The security service 138 may be configured to manage account credentials or other suitable types of secrets 115 in the secret storage 114. In some implementations, the security service 138 may be configured to receive and verify secrets 115 provided by the administrator 103 for deploying the application 112, as described below with reference to FIG. Figure 3C and 3D Described in more detail.

[0057] DRP 134 may be configured to streamline secure deployment of cloud services in private cloud 106. In some embodiments, upon receiving application advertisement 150 associated with application 122 at, for example, resource manager 122', administrator 103 of private cloud 106 may choose to deploy cloud services corresponding to application 122 in private cloud 106. Figure 3A As shown, the administrator 103 may provide the resource manager 122' with a deployment instruction 152 to initiate the DRP 134 to perform the deployment process of the application 112 in the private cloud 106. In other implementations, the administrator 103 may directly invoke the DRP 134 without using the resource manager 122'.

[0058] When initiated, the DRP 134 may be configured to perform a "bootstrapping" operation by creating a new special subscription (referred to herein as a "deployment subscription") in the private cloud 106. In one embodiment, the DRP 134 may be configured to perform a deployment / update condition check during the initial phase. If the deployment / update condition is not met, the DRP 134 stops the deployment process. If the deployment / update condition is met, the DRP 134 may create a deployment subscription for deploying the application 112. For example, Figure 3B As shown, the DRP 134 may send a subscription request 153 to a subscription service (not shown) via the resource manager 122'. In response, the subscription service may provide authorization for the requested deployment subscription. The authorization may identify one or more of the number or type of resources in the private cloud 106 that the DRP 134 can access. Unlike typical subscriptions owned by actual users 101 or administrators 103 of the private cloud 106, the deployment subscription is owned by the DRP 134 and is not visible to any actual user 101 or administrator 103 of the private cloud 106. This invisibility allows the deployment subscription to remain hidden from the user 101 while providing the ability to deploy and run new cloud services internally.

[0059] like Figure 3B As shown, upon receiving authorization for the requested deployment subscription, the DRP 134 can be configured to instantiate one or more computing resources in the private cloud 106. For example, the DRP 134 can send a resource request 159 to the compute service 136 to request instantiation of one or more virtual machines 145, and to the security service 138 to request instantiation of one or more key vaults 114. In other examples, the DRP 134 can also request a storage service (not shown) to instantiate, for example, a storage account in the repository 111', or request other suitable types of services to instantiate other suitable types of resources.

[0060] When instantiating appropriate resources such as virtual machines 145 and secret storage 114 in private cloud 106, DRP 134 can be configured to collect various types of deployment input 154 from administrator 103, such as Figure 3C As shown. In one example, the deployment input 154 may include account credentials (e.g., passwords), security credentials, and / or other suitable secrets 115 that allow cloud services to operate in the private cloud 106. The collected secrets 115 may be stored in an instantiated secret storage device 114 or other suitable location. The deployment input 154 may also include non-secret parameters, such as user preferences, etc. Such non-secret parameters may be stored in one or more instantiated storage accounts (not shown) of the DRP 134.

[0061] According to an embodiment of the disclosed technology, an application 112 to be deployed in a private cloud 106 may have a corresponding application manifest 151, for example, as an artifact of the application 112. The application manifest 151 may include data identifying one or more components of the application 112, the order in which the one or more components are installed, and / or other suitable information useful for deploying the application 112. The following is an example application manifest 151 in JSON format:

[0062]

[0063] The various attribute values ​​identified in the above example application manifest 151 are shown in the following table:

[0064]

[0065]

[0066] exist Figure 3CIn the illustrated example, DRP 134 is configured to retrieve application manifest 151 from public cloud 108 by sending deployment request 155 to public cloud 108 containing one or more secrets 115 received from administrator 103. Public cloud 108 provides application manifest 151 to DRP 134 upon authentication, for example, by authentication service 124 at public cloud 108. In other examples, application manifest 151 is provided along with application announcement 150 ( Figure 3A ) or provided to the private cloud 106 in other suitable manner.

[0067] In some implementations, the deployment request 155 may also include data representing the version number, release number, build number, and / or other suitable product / configuration parameters of the cloud platform in the private cloud 106. In one embodiment, the publishing service 126 (or other suitable service) at the public cloud 108 may be configured to select a suitable product manifest 151 based on the received parameters of the cloud platform in the private cloud 106, and provide the selected product manifest 151 to the DRP 134. Different product manifests 151 may include data identifying different components of the application 112, the order of installation, configuration parameters, and / or other suitable information.

[0068] In other embodiments, the publishing service 126 can be configured to generate the application manifest 151 based on the product / configuration parameters of the cloud platform in the private cloud 106 in an ad hoc or other suitable manner. For example, the publishing service 126 can be configured to select a subset of the available components of the application 112. In another example, the publishing service 126 can be configured to change the installation order of the components. In yet another example, the publishing service 126 can be configured to generate a custom script to be executed in the private cloud 106 during the deployment of the application 112.

[0069] In some implementations, the application manifest 151 may also include metadata that identifies one or more attributes of acceptable account credentials or other suitable types of secrets 115 for deploying cloud services. Example attributes may include keyword type, keyword length, security key format, etc. Based on the metadata in the application manifest 151, the security service 138 may be configured to determine whether the account credentials in the collected deployment input 154 have one or more attributes of acceptable account credentials. In response to determining that the collected deployment input 154 has one or more attributes of acceptable account credentials, the security service 138 may store the received secret 115 in the secret storage 114. Otherwise, the security service 138 may prompt the administrator 103 to provide updated or different deployment input 154.

[0070] Upon receiving application manifest 151, DRP 134 may be configured to install the components of application 112 directed by application manifest 151. For example, Figure 3D As shown, the DRP 134 can be configured to send one or more component requests 157 to the public cloud 108, requesting one or more components of the application 112. In response, the publishing service 126 (or other suitable type of service in the public cloud 108) can be configured to retrieve a copy of the component of the application 112' and provide the retrieved copy to the DRP 134 at the private cloud 106.

[0071] Upon receiving one or more components of application 112′, DRP 134 may be configured to use instantiated computing resources to execute one or more servers or nodes 105 ( Figure 2A ) to install one or more components. For example, Figure 3D As shown, DRP 134 can be configured to provide deployment instructions 158 (e.g., custom scripts) to one or more virtual machines 145. The virtual machines 145 can then deploy the application templates 151 ( Figure 3C ) to install the components of application 112. Such installation may include one or more of the following: creating an application catalog, copying one or more components into the application catalog, creating links to additional resources in private cloud 106, and / or other suitable operations. Then, one or more nodes 105 may execute the installed one or more components of application 112 to provide users 101 ( Figure 1 ) provides corresponding cloud services.

[0072] The DRP 134 may also store a copy of one or more components of the application 112' in the repository 111' to deploy additional instances of the application 112' or other suitable purposes. During the deployment process and / or upon completion of the deployment process, the DRP 134 may be configured to provide a deployment status 156 to the administrator 103 via the client device 102'. The deployment status 156 may include data indicating that the application 112' has been successfully deployed in the private cloud 106 or other suitable information of the deployment process.

[0073] When deploying cloud services in a cloud computing system such as a private cloud 106, multiple embodiments of the aforementioned deployment / update process can achieve a device experience. Instead of a human operator such as an administrator 103, the DRP 134 can be configured to handle operations such as creating one or more subscriptions, creating / updating / deleting resources, calling endpoints, executing custom scripts, sending various telemetry, and summaries about the deployment process and results. Therefore, one or more components of the application 112' and the associated installation order are not exposed to the administrator 103. Moreover, by using the DRP 134 to access the secrets 115 in the secret storage device 114, the risk of the stored secrets 115 being erroneously modified by the administrator 103 can be reduced. Therefore, the DRP 134 can provide an efficient service deployment experience to the administrator 103 to enable the deployment of new and / or updated cloud services in the private cloud 106.

[0074] Additionally, deployment parameters provided by the administrator 103 during the deployment / update process may be cached or otherwise remembered to avoid requesting the same input during subsequent update(s), thereby eliminating or at least reducing the risk of inconsistent values ​​provided by the user. The security service 138 may be configured to allow the administrator 103 to view all secrets 115 in the secret store 114, corresponding attributes (e.g., key length, creation / expiration date, etc.), and rotate them appropriately, either individually or all at once, or in between.

[0075] Figure 4 is a diagram illustrating an embodiment according to the disclosed technology FIG. 3A to FIG. 3D Schematic diagram of certain hardware / software components of DRP 134. Figure 4 As shown, DRP 134 may include a subscription creator 162, a resource allocator 164, and a deployment processor 166 operatively coupled to one another. Even though specific components are not shown for illustration purposes, Figure 4 1 , but in other embodiments, DRP 134 may also include input / output or other suitable types of components.

[0076] The subscription creator 162 may be configured to create a deployment subscription in response to receiving the deployment instruction 152. For example, as described above with reference to Figure 3A As described, the subscription creator 134 can be configured to send a message to the private cloud 106 ( Figure 3A ) generates and sends a subscription request 153. In response, subscription creator 162 may receive authorization for the requested deployment subscription, upon which resource allocator 164 may be configured to instantiate one or more resources by sending a resource request 159. Using the instantiated resources, deployment processor 166 may be configured to deploy the application according to application manifest 151 ( Figure 3C) retrieves one or more components of the application 112' to be deployed in the private cloud 106 and installs one or more components of the application 112'.

[0077] FIG. 5A to FIG. 5C is a flow chart illustrating various aspects of a process for streamlining secure deployment of cloud services according to an embodiment of the disclosed technology. Even though an embodiment of the process is described below in Figures 1 to 3D The process is described in the context of cloud computing environment 100, but in other embodiments, the process may be implemented in a cloud computing environment having additional and / or different components.

[0078] like Figure 5A As shown, process 200 may include receiving an application notification at stage 202. In one example, the application notification may be received by private cloud 106 ( Figure 3A ) from the public cloud 108( Figure 3A ) is received. In other embodiments, the application notification may be received by the public cloud from a publishing source, another publishing, or other suitable source. Then, process 200 may include creating a deployment subscription in stage 204. As described above with reference to Figure 3A As described, deployment subscriptions may be provided by DRP 134 ( Figure 3A ) is owned or otherwise managed or associated with, and for administrator 103 ( Figure 3A ) or any User 101( Figure 1 ) is not visible. The example operation of creating a deployment subscription is shown below. Figure 5B Describe in more detail.

[0079] Then, process 200 may include receiving an application manifest in stage 206. As described above with reference to Figure 3C As described, the application list may include identifying the application 112 ( Figure 3C ), the installation order of one or more components, and / or other suitable installation information of the application 112. Figure 5A 2 is shown after creating a deployment subscription, but in other embodiments, receiving the application list can also be performed before, interleaved with, or simultaneously with creating the deployment subscription. Then, process 200 can include deploying the application and the corresponding cloud service in private cloud 106 in stage 208. Example operations for deploying an application are described below with reference to Figure 5C Described in more detail.

[0080] like Figure 5BAs shown, example operations for creating a deployment subscription may include submitting a subscription request in stage 212. Example operations may then include receiving a subscription confirmation in stage 214. Example operations may then include allocating or otherwise obtaining access to private cloud 106 ( Figure 3A ). Example resources may include one or more of the following: a secret storage device, a virtual machine, a storage account, and / or other suitable types of computing resources in the private cloud 106.

[0081] like Figure 5C As shown, deployment application 112 ( Figure 3D ) may include retrieving components of the application in stage 222 and installing the retrieved components according to the application manifest in stage 224. The operation may also include configuring the installed components based on the application manifest in stage 226 and providing the deployment status to, for example, the administrator 103 in stage 228. Figure 3D ).

[0082] Figure 6 Is suitable for Figures 1 to 2B The computing device 300 may be suitable for some components of the cloud computing environment 100. For example, the computing device 300 may be suitable for Figures 1 to 2B Node 105 or client device 102. In a very basic configuration 302, computing device 300 may include one or more processors 304 and system memory 306. Memory bus 308 may be used to communicate between processor 304 and system memory 306.

[0083] Depending on the desired configuration, the processor 304 can be of any type, including but not limited to a microprocessor (μP), a microcontroller (μC), a digital signal processor (DSP), or any combination thereof. The processor 304 can include a multi-level cache (such as a level 1 cache 310 and a level 2 cache 312), a processor core 314, and registers 316. An example processor core 314 can include an arithmetic logic unit (ALU), a floating point unit (FPU), a digital signal processing core (DSP core), or any combination thereof. An example memory controller 318 can also be used with the processor 304, or in some implementations, the memory controller 318 can be an internal part of the processor 304.

[0084] Depending on the desired configuration, system memory 306 may be of any type, including but not limited to volatile memory (such as RAM), non-volatile memory (such as ROM, flash memory, etc.), or any combination thereof. System memory 306 may include an operating system 320, one or more applications 322, and program data 324. The basic configuration 302 described in Figure 6 The components are illustrated by those within the inner dashed line.

[0085] The computing device 300 may have additional features or functionalities and additional interfaces that support communication between the basic configuration 302 and any other devices and interfaces. For example, a bus / interface controller 330 may be used to support communication between the basic configuration 302 and one or more data storage devices 332 via a storage interface bus 334. The data storage device 332 may be a removable storage device 336, a non-removable storage device 338, or a combination thereof. Examples of removable storage devices and non-removable storage devices include magnetic disk devices (such as floppy disk drives and hard disk drives (HDDs)), optical disk drives (such as compact disk (CD) drives or digital versatile disk (DVD) drives), solid state drives (SSDs), and tape drives, to name a few. Example computer storage media may include volatile and non-volatile media, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). The term "computer-readable storage medium" or "computer-readable storage device" excludes propagating signals and communication media.

[0086] System memory 306, removable storage 336, and non-removable storage 338 are examples of computer-readable storage media. Computer-readable storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by computing device 300. Any such computer-readable storage medium may be part of computing device 300. The term "computer-readable storage medium" excludes propagating signals and communications media.

[0087] The computing device 300 may also include an interface bus 340 to support communications from various interface devices (e.g., output devices 342, peripheral interfaces 344, and communication devices 346) to the basic configuration 302 via the bus / interface controller 330. Example output devices 342 include a graphics processing unit 348 and an audio processing unit 350, which may be configured to communicate with various external devices such as a display or speakers via one or more A / V ports 352. Example peripheral interfaces 344 include a serial interface controller 354 or a parallel interface controller 356, which may be configured to communicate with external devices such as input devices (e.g., keyboards, mice, pens, voice input devices, touch input devices, etc.) or other peripheral devices (e.g., printers, scanners, etc.) via one or more I / O ports 358. Example communication devices 346 include a network controller 360, which may be arranged to support communications with one or more other computing devices 362 over a network communication link via one or more communication ports 364.

[0088] A network communication link can be an example of a communication medium. Communication media can generally be implemented by computer-readable instructions, data structures, program modules, or other data in a modulated data signal (such as a carrier wave or other transport mechanism, etc.), and can include any information delivery medium. A "modulated data signal" can be a signal that sets or changes one or more of its characteristics in such a way that the information in the signal is encoded. By way of example and not limitation, communication media can include wired media such as a wired network or a direct wired connection and wireless media such as acoustic, radio frequency (RF), microwave, infrared (IR) and other wireless media. The term computer-readable medium used herein can include storage media and communication media.

[0089] The computing device 300 may be implemented as part of a small portable (or mobile) electronic device such as a cell phone, a personal data assistant (PDA), a personal media player, a wireless web viewing device, a personal headset device, a dedicated device, or a hybrid device including any of the above functions. The computing device 300 may also be implemented as a personal computer, including laptop and non-laptop computer configurations.

[0090] Through the foregoing, it can be understood that the specific embodiments of the present disclosure have been described herein for illustrative purposes, but various modifications can be made without departing from the present disclosure. In addition, in addition to or in place of the elements of other embodiments, many elements of one embodiment can be combined with other embodiments. Therefore, except for the attached claims, the present technology is not limited.

Claims

1. A method for streamlined secure deployment in a cloud computing system, the cloud computing system being configured to perform a deployment service, the method comprising: receiving an instruction to deploy an application in the cloud computing system; retrieving a manifest for the application based on the instruction, the manifest identifying a plurality of components of the application and an installation order for the plurality of components; A deployment subscription is created for the application in the cloud computing system by the deployment service and based on the manifest, wherein: The deployment subscription is automatically created without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and The deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and Resources in the cloud computing system for executing the application are instantiated based at least in part on the deployment subscription.

2. The method according to claim 1, wherein instantiating the resources in the cloud computing system for executing the application comprises: creating a catalog for a component of the plurality of components of the application; as well as Copy the component into the directory.

3. The method according to claim 1, further comprising: retrieving a component of the plurality of components of the application using the resource; installing the component in the cloud computing system; as well as The installed component is executed to provide access to the application for the user of the cloud computing system without exposing the installed component to the user of the cloud computing system. 4 . The method of claim 3 , further comprising collecting account credentials from the administrator of the cloud computing system, wherein retrieving the component uses the account credentials collected from the administrator of the cloud computing system.

5. The method according to claim 4, wherein: The manifest includes metadata identifying attributes of acceptable account credentials; Instantiating the resource includes instantiating a secret storage device; and The method further comprises: determining that the account credentials collected from the administrator of the cloud computing system include the attributes of the acceptable account credentials; as well as In response to determining that the account credentials collected from the administrator of the cloud computing system include the attributes of the acceptable account credentials, the account credentials are stored in the secret storage.

6. The method according to claim 1, further comprising: retrieving the plurality of components of the application using the resource; installing the plurality of components of the application in the cloud computing system according to the installation order for the plurality of components; as well as The installed plurality of components of the application are executed to provide access to the application for the user of the cloud computing system without exposing the installed plurality of components to the user of the cloud computing system.

7. The method of claim 1 , wherein creating the deployment subscription comprises: sending a request for the deployment subscription from the deployment service to a resource manager of the cloud computing system; as well as An authorization to create the deployment subscription is received from the resource manager of the cloud computing system, the authorization identifying at least one of a quantity or a type of the resources.

8. The method according to claim 1, wherein: Instantiating the resource in the cloud computing system includes instantiating a secret storage device; and the method further includes: collecting account credentials of the administrator from the cloud computing system; storing the account credentials collected from the administrator of the cloud computing system in the secret storage device; and Based on the account credentials stored in the secret storage device, another application is deployed in the cloud computing system instead of collecting the account credentials again from the administrator of the cloud computing system.

9. The method according to claim 1, wherein: The cloud computing system includes a private cloud computing system; and The method further comprises: receiving a notification from a public cloud computing system indicating that the application is available for deployment or update in the private cloud computing system; and In response to receiving the notification, the instruction is generated, the instruction being used for the deployment service to create the deployment subscription for the application in the cloud computing system.

10. A computing device in a cloud computing system, the computing device being configured to perform a deployment service, the computing device comprising: processor; as well as a memory operably coupled to the processor, the memory containing instructions executable by the processor to: receiving an instruction to deploy an application in the cloud computing system; retrieving a manifest for the application based on the instruction, the manifest identifying a plurality of components of the application and an installation order for the plurality of components; Based on the list, a deployment subscription is created for the application in the cloud computing system, wherein: The deployment subscription is automatically created without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and The deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and Resources in the cloud computing system for executing the application are instantiated based at least in part on the deployment subscription.

11. The computing device of claim 10, wherein instantiating the resources in the cloud computing system for executing the application comprises: creating a catalog for a component of the plurality of components of the application; as well as Copy the component into the directory.

12. The computing device of claim 10, wherein the instructions are further executable by the processor to: retrieving a component of the plurality of components of the application using the resource; Installing the component in the cloud computing system; and The installed component is executed to provide access to the application for the user of the cloud computing system without exposing the installed component to the user of the cloud computing system.

13. The computing device of claim 12, wherein the instructions are further executable by the processor to collect account credentials from the administrator of the cloud computing system, wherein retrieving the component uses the account credentials collected from the administrator of the cloud computing system.

14. The computing device of claim 13, wherein: The manifest includes metadata identifying attributes of acceptable account credentials; Instantiating the resource comprises instantiating a secret store; and The instructions are also executable by the processor to: determining that the account credentials collected from the administrator of the cloud computing system include the attributes of the acceptable account credentials; and In response to determining that the account credentials collected from the administrator of the cloud computing system include the attributes of the acceptable account credentials, the account credentials are stored in the secret storage.

15. The computing device of claim 10, wherein the instructions are further executable by the processor to: retrieving the plurality of components of the application using the resource; installing the plurality of components of the application in the cloud computing system according to the installation order for the plurality of components; and The installed plurality of components of the application are executed to provide access to the application for the user of the cloud computing system without exposing the installed plurality of components to the user of the cloud computing system.

16. The computing device of claim 10, wherein creating the deployment subscription comprises: sending a request for the deployment subscription from the deployment service to a resource manager of the cloud computing system; as well as An authorization to create the deployment subscription is received from the resource manager of the cloud computing system, the authorization identifying at least one of a quantity or a type of the resources.

17. The computing device of claim 10, wherein: Instantiating the resource in the cloud computing system includes instantiating a secret storage device; and The instructions are also executable by the processor to: collecting account credentials of the administrator from the cloud computing system; storing the account credentials collected from the administrator of the cloud computing system in the secret storage device; as well as Based on the account credentials stored in the secret storage device, another application is deployed in the cloud computing system instead of collecting the account credentials again from the administrator of the cloud computing system.

18. A computer-readable storage medium operably coupled to a processor and containing instructions executable by the processor to: receiving instructions for deploying an application in a cloud computing system; retrieving a manifest for the application based on the instruction, the manifest identifying a plurality of components of the application and an installation order for the plurality of components; Based on the list, a deployment subscription is created for the application in the cloud computing system, wherein: The deployment subscription is automatically created without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and The deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and Resources in the cloud computing system for executing the application are instantiated based at least in part on the deployment subscription.