Systems and methods for customizing a cloud console for use with a cloud environment.

A customizable cloud console is implemented via a configuration service, addressing the lack of brand identity and management in existing cloud environments, enabling tailored access and enhanced control for third-party operators.

JP2026515878APending Publication Date: 2026-05-19ORACLE INT CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
ORACLE INT CORP
Filing Date
2024-04-25
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing cloud environments lack mechanisms for customizable consoles that allow for brand identity and efficient management of cloud-based products and services, limiting the ability of third-party operators to provide tailored experiences for customers.

Method used

A customizable cloud console is provided through a configuration service that generates console configuration resources based on instructions from a first entity, allowing for personalized customization and debugging of the console.

Benefits of technology

Enables third-party operators to provide branded and efficient access to cloud-based products and services, enhancing customer experience and control over cloud environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026515878000001_ABST
    Figure 2026515878000001_ABST
Patent Text Reader

Abstract

The systems and methods described herein provide a customizable console for use in conjunction with providing a cloud environment. The provision of cloud computing enables third-party operators, acting as resellers of products or services owned or managed by the cloud provider, to access the cloud environment. The operator provides access to customers through a customizable console, allowing for more granular control over cloud-based products and services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Copyright Information Part of the disclosure of this patent document contains materials that are subject to copyright protection. The copyright owner reserves all copyrights, notwithstanding any objection to the full reproduction of the patent document or patent disclosure by anyone when it appears in the patent file or patent records of the Patent and Trademark Office.

[0002] Claims of Priority and Cross - References to Related Applications This application relates to U.S. Patent Provisional Application No. 63 / 462,868, “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE,” filed on April 28, 2023, U.S. Patent Provisional Application No. 63 / 462,875, “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE,” filed on April 28, 2023, and U.S. Patent Provisional Application No. 63 / 462,878, “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING U.S. Patent Provisional Application No. 63 / 462,880, filed on April 28, 2023, "SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE", U.S. Patent Provisional Application No. 63 / 462,882, filed on April 28, 2023, "SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE", U.S. Patent Provisional Application No. 63 / 462,885, filed on April 28, 2023, "SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING "INFRASTRUCTURE," and U.S. Patent Application No. 18 / 639 filed on April 18, 2024.Claiming priority to Patent No. 777, "SYSTEM AND METHOD FOR CUSTOMIZING A CLOUD CONSOLE FOR USE WITH CLOUD ENVIRONMENTS," each of the above applications and its contents are incorporated herein by reference.

[0003] Technical field Embodiments described herein generally relate to systems and methods for providing a cloud environment for use by tenants of a cloud infrastructure environment in accessing environment-related software products, services, or other offerings, including providing a console debug mode for a custom console. [Background technology]

[0004] background Cloud computing environments can be used to provide access to a variety of complementary cloud-based components, such as software applications or services, enabling organizations or enterprise customers to operate applications and services within a highly available hosted environment.

[0005] The benefits for organizations in migrating their application and service needs to a cloud environment include reducing the cost and complexity of designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other information technology infrastructure, allowing them to instead focus on managing their day-to-day business. [Overview of the project] [Problems that the invention aims to solve]

[0006] overview In some cloud environments, it is desirable to provide mechanisms that allow for the customization of consoles, such as those provided by the cloud environment. This would allow, for example, the customization of the look and feel of publicly accessible pages or consoles, or pages accessible by customers. Such customization is desirable, for example, to promote brand identity and loyalty, or to facilitate efficient brand identification or ownership of pages or consoles.

[0007] Embodiments described herein generally relate to systems and methods for providing a cloud environment for use by tenants of a cloud infrastructure environment to access environment-related software products, services, or other offerings, including customizing a cloud console.

[0008] The systems and methods described herein provide a customizable console. Cloud computing offerings (e.g., private label cloud computing offerings) enable third-party operators, acting as resellers of products or services owned or managed by the cloud provider, to access the cloud environment. The operator provides access to customers through a customizable console, allowing for greater control over cloud-based products and services.

[0009] According to the embodiment, the method can provide a computer equipped with a microprocessor. The method can provide a customizable console in a cloud environment, which provides access to subscription-based products, services, and other offerings. The method can provide access to the customizable console in a cloud environment. The method can customize the customizable console via a configuration service by a first entity associated with a first tenancy in a cloud environment, which generates console configuration resources in response to instructions received from the first entity associated with the first tenancy, and the generated console configuration resources are used to customize the customizable console when access to the customizable console is provided.

[0010] According to the embodiment, the method can provide a computer equipped with a microprocessor. The method can provide a customizable console in a cloud environment, the customizable console providing access to subscription-based products, services, and other offerings. The method can customize the customizable console via a configuration service, the configuration service generating console configuration resources in response to received instructions. Based on the generated console configuration resources, the method can generate a modified preview of the console containing multiple console elements based on the generated console configuration resources for use in debugging the generated console configuration resources. [Brief explanation of the drawing]

[0011] [Figure 1] This figure shows a system for providing a cloud infrastructure environment according to an embodiment. [Figure 2]This figure further illustrates how a cloud infrastructure environment may be used to provide cloud-based applications or services according to the embodiment. [Figure 3] This figure shows an exemplary cloud infrastructure architecture according to an embodiment. [Figure 4] This figure shows another example of a cloud infrastructure architecture according to an embodiment. [Figure 5] This figure shows another example of a cloud infrastructure architecture according to an embodiment. [Figure 6] This figure shows another example of a cloud infrastructure architecture according to an embodiment. [Figure 7] This figure shows a system that provides a dedicated label cloud environment or private label cloud environment for use by tenants or customers of a cloud infrastructure environment, according to an embodiment. [Figure 8] This figure further illustrates the use of a cloud realm for use by a tenant or customer of a cloud infrastructure environment, according to an embodiment. [Figure 9] This figure further illustrates the use of a cloud realm for use by a tenant or customer of a cloud infrastructure environment, according to an embodiment. [Figure 10] This figure shows a system, according to an embodiment, for providing access to software products or services in a cloud computing environment or other computing environment. [Figure 11] This figure shows an architecture for providing console customization according to an embodiment. [Figure 12] This figure shows multiple paths for providing console customization according to the embodiment. [Figure 13] This is a lifecycle diagram of backend resources for console customization according to an embodiment. [Figure 14]A diagram of a user interface for console customization according to an embodiment. [Figure 15] A diagram of a user interface for console customization according to an embodiment. [Figure 16] A diagram of a user interface for console customization according to an embodiment. [Figure 17] A diagram showing a color space used for custom palette generation for console customization according to an embodiment. [Figure 18] A flowchart of a method for generating a customizable console according to an embodiment. [Figure 19] A diagram showing an architecture for providing a debug mode for console customization according to an embodiment. [Figure 20] A diagram showing a screenshot of the debug mode according to an embodiment. [Figure 21] A flowchart of a method for console debug mode for a custom console according to an embodiment.

Mode for Carrying Out the Invention

[0012] Detailed Description A cloud computing or cloud infrastructure environment can be used to provide access to various complementary cloud-based components such as software applications or services that enable an organization or a corporate customer to operate applications and services within a highly available hosted environment.

[0013] The benefits for organizations in migrating their application and service needs to a cloud infrastructure environment include reducing the cost and complexity of designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other information technology infrastructure, allowing them to instead focus on managing their day-to-day business.

[0014] Cloud infrastructure environment Figures 1 and 2 show a system for providing a cloud infrastructure environment according to an embodiment.

[0015] According to the embodiments, components and processes, such as those shown in Figure 1 and further described herein with respect to various embodiments, may be provided as software or program code that can be executed by a computer system or other type of processing device, such as a cloud computing system.

[0016] The examples provided are intended to illustrate computing environments that may be used to provide a dedicated-label or private-label cloud environment for use by tenants of a cloud infrastructure in accessing subscription-based software products, services, or other offerings related to the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein may be used in conjunction with other types of cloud computing environments.

[0017] As shown in Figure 1, according to the embodiment, the cloud infrastructure environment 100 can operate on a cloud computing infrastructure 102 which includes hardware (e.g., processors, memory), software resources, and one or more cloud interfaces 104 or other application program interfaces (APIs) that provide access to cloud resources shared via one or more load balancers 106.

[0018] According to the embodiment, the cloud infrastructure environment supports the use of availability domains, such as availability domains A180 and B182, which enables customers to create and access cloud networks 184 and 186 and run cloud instances A192 and B194.

[0019] According to the embodiment, tenancies can be created for each cloud tenant / customer, for example, tenants A142, B144, thereby providing secure, isolated partitions within a cloud infrastructure environment where customers can create, organize, and manage cloud resources. Cloud tenants / customers can access each of their cloud instances by accessing availability domains and cloud networks.

[0020] According to the embodiment, for example, a client device such as a computing device 160 having device hardware 162 (e.g., a processor, memory) and a graphical user interface 166 may enable administrators, other users, etc., to communicate with a cloud infrastructure environment via a network such as a wide area network, a local area network, or the internet to create or update cloud services.

[0021] According to one embodiment, the cloud infrastructure environment provides access to shared cloud resources 140, for example, via a compute resource layer 150, a network resource layer 164, and / or a storage resource layer 170. Customers can launch cloud instances as needed to meet their compute and application requirements. After the customer provisions and launches the cloud instances, the provisioned cloud instances can be accessed, for example, from client devices.

[0022] According to the embodiment, the compute resource layer may include resources such as, for example, bare metal cloud instances 152, virtual machines 154, graphical processing unit (GPU) compute cloud instances 156, and / or containers 158. The compute resource layer may be used, for example, to provision and manage bare metal compute cloud instances, as in an on-premises data center, or to provision cloud instances as needed to deploy and run applications.

[0023] For example, according to one embodiment, the cloud infrastructure environment can provide control over physical host (bare metal) machines in the compute resource layer that run directly as compute cloud instances on bare metal servers without using a hypervisor.

[0024] According to one embodiment, the cloud infrastructure environment may also provide control over virtual machines in a compute resource tier that can be launched from an image, for example, and the type and amount of resources available to a virtual machine cloud instance may be determined based on the image from which the virtual machine was launched.

[0025] According to one embodiment, the network resource layer may include multiple network-related resources, such as a virtual cloud network (VCN) 165, a load balancer 167, an edge service 168, and / or connectivity service 169.

[0026] According to one embodiment, the storage resource layer may include multiple resources, such as a data / block volume 172, file storage 174, object storage 176, and / or local storage 178.

[0027] As shown in Figure 2, according to the embodiment, the cloud infrastructure environment may include various complementary cloud-based components as cloud infrastructure applications and services 200, for example, enabling customers of an organization or enterprise to operate applications and services in a highly available hosted environment.

[0028] For example, according to the embodiment, a self-contained cloud region can be provided as a complete, for example, Oracle Cloud Infrastructure (OCI)-dedicated region within an organization's data center, providing data center operators with the agility, scalability, and cost-effectiveness of the public cloud while maintaining complete control over data and applications to meet security, regulatory, or data residency requirements.

[0029] For example, according to one embodiment, such an environment may include racks physically managed by the cloud infrastructure provider, customer racks, access for cloud operators for configuration and hardware support, power and cooling for the customer's data center, customer floor space, area for customer data center personnel, and physical access cages.

[0030] According to the embodiment, a dedicated region provides tenants / customers with the same set of IaaS (infrastructure-as-a-service), PaaS (platform-as-a-service), and SaaS (software-as-a-service) products or services available within the cloud infrastructure provider's public cloud region, such as ERP, Financials, HCM, and SCM. Customers can seamlessly upscale and shift their traditional workloads using the cloud infrastructure provider's services (e.g., bare metal computing, VMs, and GPUs), database services (e.g., autonomous databases), or container-based services (e.g., Kubernetes container engines).

[0031] According to one embodiment, the cloud infrastructure environment can operate according to an IaaS (infrastructure-as-a-service) model that enables the environment to provide virtualized computing resources over a public network (e.g., the internet).

[0032] In the IaaS model, a cloud infrastructure provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer)). In some cases, the cloud infrastructure provider may also provide various services that accompany those infrastructure components (examples of services include billing software, monitoring software, logging software, load balancing software, or clustering software). Therefore, since these services can be policy-driven, IaaS users may implement policies to drive load balancing and maintain application availability and performance.

[0033] According to the embodiment, an IaaS customer may access resources and services via a wide area network (WAN), such as the internet, and install the remaining elements of their application stack using the services of a cloud infrastructure provider. For example, a user can log into an IaaS platform, create virtual machines (VMs), install operating systems (OS) on each VM, deploy middleware such as databases, create storage buckets for workloads and backups, and also install enterprise software on those VMs. The customer can then use the provider's services to perform a variety of functions, including balancing network traffic, troubleshooting application issues, monitoring performance, or managing disaster recovery.

[0034] In some embodiments, the cloud infrastructure provider may, but does not have to be, a third-party service specializing in providing IaaS (e.g., providing, leasing, selling). The entity may also choose to deploy a private cloud and become its own provider of infrastructure services.

[0035] In one embodiment, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server, etc. This process may also include the process of preparing the server (e.g., installing libraries or daemons). This process is often managed by the cloud infrastructure provider under the hypervisor layer (e.g., servers, storage, network hardware, and virtualization). Thus, the customer may be responsible for handling the deployment of the OS, middleware, and / or applications (e.g., on self-service virtual machines, etc., which can be spun up on demand).

[0036] In some embodiments, IaaS provisioning may also refer to acquiring computers or virtual hosts for use and installing any necessary libraries or services on those computers or virtual hosts. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.

[0037] Depending on the embodiment, the challenges of IaaS provisioning include the first challenge of provisioning an initial set of infrastructure before anything is done. Secondly, there is the challenge of developing the existing infrastructure after everything has been provisioned (e.g., adding new services, modifying services, or removing services). In some cases, these two challenges may be addressed by allowing the configuration of the infrastructure to be defined declaratively. In other words, the infrastructure (e.g., which components are needed and how those components interact) can be defined by one or more configuration files. In this way, the entire topology of the infrastructure (e.g., which resources depend on which resources and how each of those resources works together) can be described declaratively. In some cases, after the topology is defined, a workflow may be generated to create and / or manage the various components described in the configuration files.

[0038] In some embodiments, the cloud infrastructure may include many interconnected elements. For example, there may be one or more virtual private clouds (VPCs), also known as core networks (e.g., configurable and / or shared computing resources, possibly on-demand pools). In some examples, there may also be one or more inbound / outbound traffic group rules provisioned to define how inbound and / or outbound traffic on the network is configured, as well as one or more virtual machines (VMs). Other infrastructure elements such as load balancers and databases may also be provisioned. The infrastructure can evolve gradually as more infrastructure elements are desired and / or added.

[0039] In some embodiments, continuous deployment techniques may be employed to enable the deployment of infrastructure code across various virtual computing environments. Furthermore, the techniques described can enable infrastructure management within these environments. In some examples, a service team may write code that is desirable to be deployed to one or more, but often many, different production environments (e.g., across various geographical locations). However, in some examples, the infrastructure to which the code is deployed must be configured first. In some cases, provisioning may be performed manually, and provisioning tools may be used to provision resources and / or deployment tools may be used to deploy the code after the infrastructure has been provisioned.

[0040] Figure 3 shows an exemplary cloud infrastructure architecture according to an embodiment.

[0041] As shown in Figure 3, according to the embodiment, the service operator 202 can be communicably coupled to a secure host tenancy 204 which may include a virtual cloud network (VCN) 206 and a secure host subnet 208.

[0042] In some cases, a service operator may use one or more client computing devices, which may be portable handheld devices (e.g., telephones, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., head-mounted displays) with the Internet, email, short message service (SMS), or other communication protocols enabled, running software such as Microsoft Windows® and / or various mobile operating systems such as iOS® and Android®. Alternatively, a client computing device may be a general-purpose personal computer, including, for example, personal computers and / or laptop computers running various versions of the Microsoft Windows, Apple Macintosh®, and / or Linux® operating systems. A client computing device may also be a workstation computer running any of the various commercially available UNIX® or UNIX-like operating systems, including, but not limited to, various GNU / Linux operating systems such as Chrome®. Alternatively or additionally, the client computing device may be any other electronic device, such as a thin client computer, an internet-enabled gaming system (e.g., a Microsoft Xbox® game console), and / or a personal messaging device, that can communicate over a network and / or the Internet that has access to the VCN.

[0043] According to one embodiment, the VCN may include a local peering gateway (LPG) 210 that can be communicatively coupled to a secure shell (SSH) VCN 212 via an LPG included in the SSH VCN. The SSH VCN may include an SSH subnet 214, and the SSH VCN may be communicatively coupled to a control plane VCN 216 via an LPG included in the control plane VCN. The SSH VCN may also be communicatively coupled to a data plane VCN 218 via an LPG. The control plane VCN and the data plane VCN may be included in a service tenancy 219 that may be owned and / or operated by a cloud infrastructure provider.

[0044] According to the embodiment, the control plane VCN may include a control plane demilitarized zone (DMZ) layer 220 that functions as a perimeter network (e.g., part of the corporate network between the corporate intranet and the external network). Servers based on the DMZ may have limited responsibilities that help contain potential breaches. Furthermore, the DMZ layer may include a control plane application layer 224 that may include one or more load balancer (LB) subnets 222 and application subnets 226, and a control plane data layer 228 that may include database (DB) subnets 230 (e.g., a front-end DB subnet and / or a back-end DB subnet). The LB subnets included in the control plane DMZ layer may be communicably coupled to application subnets and an internet gateway 234 included in the control plane application layer which may be included in the control plane VCN, and the application subnets may be communicably coupled to DB subnets included in the control plane data layer, as well as a service gateway 236 and a network address translation (NAT) gateway 238. The control plane VCN may include service gateways and NAT gateways.

[0045] According to one embodiment, the control plane VCN may include a data plane mirror application layer 240 which may include application subnets. The application subnets included in the data plane mirror application layer may include virtual network interface controllers (VNICs) on which compute instances can run. The compute instances can communicately connect the application subnets of the data plane mirror application layer to application subnets that may be included in the data plane application layer.

[0046] According to the embodiment, the data plane VCN may include a data plane application layer 246, a data plane DMZ layer 248, and a data plane data layer 250. The data plane DMZ layer may include an application subnet of the data plane application layer and an LB subnet that can be communicatively coupled to the internet gateway of the data plane VCN. The application subnet may be communicatively coupled to the service gateway of the data plane VCN and the NAT gateway of the data plane VCN. The data plane data layer may also include a DB subnet that can be communicatively coupled to the application subnet of the data plane application layer.

[0047] According to the embodiment, the internet gateways of the control plane VCN and the data plane VCN may be communicably coupled to a metadata management service 252 which may be communicably coupled to the public internet 254. The public internet may be communicably coupled to the NAT gateways of the control plane VCN and the data plane VCN. The service gateways of the control plane VCN and the data plane VCN may be communicably coupled to a cloud service 256.

[0048] According to the embodiment, a service gateway of a control plane VCN or a data plane VCN can make application programming interface (API) calls to a cloud service without traversing the public internet. API calls from the service gateway to the cloud service can be one-way, with the service gateway making the API call to the cloud service and the cloud service sending the requested data to the service gateway. Generally, the cloud service does not need to initiate the API call to the service gateway.

[0049] According to the embodiment, a secure host tenancy can be directly connected to a service tenancy, or otherwise may be isolated. A secure host subnet can communicate with an SSH subnet via an LPG, which can enable bidirectional communication on otherwise isolated systems. Connecting a secure host subnet to an SSH subnet may give the secure host subnet access to other entities within the service tenancy.

[0050] According to one embodiment, the control plane VCN may allow users of the service tenancy to configure or otherwise provision the desired resources. The desired resources provisioned within the control plane VCN may be deployed or otherwise used in the data plane VCN. In some examples, the control plane VCN can be separated from the data plane VCN, and the data plane mirror application layer of the control plane VCN can communicate with the data plane application layer of the data plane VCN via VNICs that may be included in the data plane mirror application layer and the data plane application layer.

[0051] According to the embodiment, a user or customer of the system can perform requests, such as create, read, update, or delete (CRUD) operations, over the public internet, which can transmit the requests to a metadata management service. The metadata management service can transmit the requests to the control plane VCN via an internet gateway. The requests may be received by an LB subnet included in the control plane DMZ layer. The LB subnet may determine that the request is valid, and in response to this determination, the LB subnet may send the request to an application subnet included in the control plane application layer. If the validity of the request is confirmed and the request requires a call to the public internet, the call to the internet may be sent to a NAT gateway capable of making internet calls. The metadata to be stored by the request may be stored in a DB subnet.

[0052] According to the embodiment, the data plane mirror application layer can facilitate direct communication between the control plane VCN and the data plane VCN. For example, it may be desirable that changes, updates, or other appropriate modifications to the configuration be applied to the resources contained in the data plane VCN. Using the VNIC, the control plane VCN can communicate directly with the resources contained in the data plane VCN, thereby enabling changes, updates, or other appropriate modifications to the configuration of the resources.

[0053] According to this embodiment, the control plane VCN and the data plane VCN may be included in the service tenancy. In this case, the system user or customer does not have to own or operate either the control plane VCN or the data plane VCN. Instead, the cloud infrastructure provider may own or operate the control plane VCN and the data plane VCN, both of which may be included in the service tenancy. This embodiment can enable network isolation, which can prevent the user or customer from exchanging information with the resources of other users or other customers. This embodiment may also enable the system user or customer to store databases privately without having to rely on the public internet for storage, which may not provide the desired level of threat protection.

[0054] According to this embodiment, the LB subnet included in the control plane VCN may be configured to receive signals from the service gateway. In this embodiment, the control plane VCN and the data plane VCN may be configured to be invoked by the cloud infrastructure provider's customers without calling the public internet. The cloud infrastructure provider's customers may desire this embodiment because the databases they use may be controlled by the cloud infrastructure provider and stored in a service tenancy that can be isolated from the public internet.

[0055] Figure 4 shows another example of a cloud infrastructure architecture according to an embodiment.

[0056] As shown in Figure 4, according to this embodiment, the data plane VCN may be included in the customer tenancy 221. In this case, the cloud infrastructure provider may provide a control plane VCN for each customer, and the cloud infrastructure provider may configure a unique compute instance included in the service tenancy for each customer. Each compute instance may enable communication between the control plane VCN included in the service tenancy and the data plane VCN included in the customer tenancy. The compute instance may enable resources provisioned within the control plane VCN included in the service tenancy to be deployed, or otherwise used, in the data plane VCN included in the customer tenancy.

[0057] In one embodiment, a customer of a cloud infrastructure provider may have a database that is managed and operates within the customer's tenancy. In this example, the control plane VCN may include a data plane mirror app layer that may include app subnets. The data plane mirror app layer may reside in the data plane VCN, but does not have to be provided in the data plane VCN. That is, the data plane mirror app layer may have access rights to the customer's tenancy, but does not have to reside in the data plane VCN, and does not have to be owned or operated by the customer. The data plane mirror app layer may be configured to make calls to the data plane VCN, but does not have to be configured to make calls to any entities contained within the control plane VCN. The customer may want to deploy, or otherwise use, resources in the data plane VCN that are provisioned within the control plane VCN, and the data plane mirror app layer can facilitate the customer's desired deployment or other use of resources.

[0058] In one embodiment, a customer of a cloud infrastructure provider can apply filters to data plane VCNs. In this embodiment, the customer can determine which data plane VCNs are accessible, and may restrict access from data plane VCNs to the public internet. The cloud infrastructure provider does not need to be able to apply filters or otherwise control access of data plane VCNs to any external network or database. Applying filters and controls to data plane VCNs included in the customer's tenancy can help isolate the data plane VCNs from other customers and from the public internet.

[0059] According to the embodiment, a cloud service may be invoked by a service gateway to access services that may not exist on the public internet, a control plane VCN, or a data plane VCN. The connection between the cloud service and the control plane VCN or data plane VCN does not have to be continuous. The cloud service may reside on different networks owned or operated by the cloud infrastructure provider. The cloud service may be configured to receive calls from the service gateway and not to receive calls from the public internet. Some cloud services may be isolated from others, and the control plane VCN may be isolated from cloud services that may not be in the same region as the control plane VCN.

[0060] For example, according to one embodiment, the control plane VCN may be located in "Region 1," and the cloud service "Deployment 1" may be located in both Region 1 and "Region 2." When a service gateway included in the control plane VCN located in Region 1 makes a call to Deployment 1, this call may be sent to Deployment 1 within Region 1. In this example, the control plane VCN, or Deployment 1 within Region 1, may or may not communicate with Deployment 1 within Region 2.

[0061] Figure 5 shows another example of a cloud infrastructure architecture according to an embodiment.

[0062] As shown in Figure 5, according to the embodiment, a trusted application subnet 260 can be communicatively coupled to a service gateway included in the data plane VCN, a NAT gateway included in the data plane VCN, and a DB subnet included in the data plane data layer. An untrusted application subnet 264 can be communicatively coupled to a service gateway included in the data plane VCN and a DB subnet included in the data plane data layer. The data plane data layer may include a DB subnet that can be communicatively coupled to a service gateway included in the data plane VCN.

[0063] According to one embodiment, an untrusted application subnet may include one or more primary VNICs (1) to (N) that can be communicatively coupled to tenant virtual machines (VMs). Each tenant VM may be communicatively coupled to each application subnet 267 (1) to (N) that may be included in each container exit VCN 268 (1) to (N) that may be included in each customer tenancy 270 (1) to (N). Each secondary VNIC can facilitate communication between the untrusted application subnet included in the data plane VCN and the application subnet included in the container exit VCN. Each container exit VCN may include a NAT gateway that can be communicatively coupled to the public internet.

[0064] According to the embodiment, the public internet may be communicatively coupled to a NAT gateway, which is included in the control plane VCN and the data plane VCN. A service gateway, which is included in the control plane VCN and the data plane VCN, may be communicatively coupled to a cloud service.

[0065] According to one embodiment, the data plane VCN can be integrated with a customer's tenancy. This integration may be useful or desirable for a cloud infrastructure provider's customer when they may require additional support when executing code. For example, a customer may provide code that could potentially be destructive, communicate with other customers' resources, or otherwise cause undesirable consequences.

[0066] According to one embodiment, a customer of a cloud infrastructure provider may request the cloud infrastructure provider to grant temporary network access privileges and the ability to connect to the data plane application layer. The code for performing this function may run in a VM and may not be configured to run elsewhere on the data plane VCN. Each VM may be connected to one customer's tenancy. Each container (1) to (N) contained within a VM may be configured to run the code. In this case, a double isolation may exist (e.g., the container running the code, the container may be contained in at least one VM that is in an untrusted application subnet), which can help prevent incorrect or otherwise undesirable code from damaging the cloud infrastructure provider's network or the networks of different customers. The containers may be communicatively coupled to the customer's tenancy and may be configured to send or receive data to or from the customer's tenancy. The containers may not be configured to send or receive data to or from any other entities within the data plane VCN. Upon completion of code execution, the cloud infrastructure provider may discard the containers.

[0067] In one embodiment, a trusted application subnet may execute code that may be owned or operated by the cloud infrastructure provider. In this embodiment, the trusted application subnet may be communicatively joined to a DB subnet and configured to perform CRUD operations within the DB subnet. An untrusted application subnet may be communicatively joined to a DB subnet and configured to perform read operations within the DB subnet. Containers that may be contained within each customer's VM and can execute code from the customer do not need to be communicatively joined to the DB subnet.

[0068] In some embodiments, the control plane VCN and the data plane VCN do not need to be directly communicatively coupled, or direct communication between the control plane VCN and the data plane VCN is not required. However, communication can occur indirectly, and a LPG (Landing Platform) may be established by the cloud infrastructure provider to facilitate communication between the control plane VCN and the data plane VCN. In another example, the control plane VCN or the data plane VCN can make calls to cloud services via a service gateway. For example, a call from the control plane VCN to a cloud service may include a request to a service that can communicate with the data plane VCN.

[0069] Figure 6 shows another example of a cloud infrastructure architecture according to an embodiment.

[0070] As shown in Figure 6, according to the embodiment, a trusted application subnet can be communicatively coupled to a service gateway included in the data plane VCN, a NAT gateway included in the data plane VCN, and a DB subnet included in the data plane data layer. An untrusted application subnet can be communicatively coupled to a service gateway included in the data plane VCN and a DB subnet included in the data plane data layer. The data plane data layer may include a DB subnet that can be communicatively coupled to a service gateway included in the data plane VCN.

[0071] According to one embodiment, an untrusted application subnet may include a primary VNIC that can be communicatively coupled to tenant virtual machines (VMs) residing within the untrusted application subnet. Each tenant VM may execute code within its respective container and may be communicatively coupled to an application subnet that may be included in a dataplane application layer 281, which may be included in a container exit VCN 280. Each secondary VNIC 282(1)-(N) can facilitate communication between the untrusted application subnet included in the dataplane VCN and the application subnet included in the container exit VCN. The container exit VCN may include a NAT gateway that can be communicatively coupled to the public internet.

[0072] According to the embodiment, an internet gateway included in the control plane VCN and included in the data plane VCN may be communicatively coupled to a metadata management service which may be communicatively coupled to the public internet. The public internet may be communicatively coupled to a NAT gateway included in the control plane VCN and included in the data plane VCN. A service gateway included in the control plane VCN and included in the data plane VCN may be communicatively coupled to a cloud service.

[0073] In this embodiment, the pattern shown in Figure 6 may be considered an exception to the pattern shown in Figure 5, which may be desirable for a customer when the cloud infrastructure provider cannot communicate directly with the customer (e.g., a disconnected region). Each container contained within a VM for each customer may be accessible in real time by the customer. The container may be configured to make calls to each secondary VNIC contained within the application subnet of the data plane application layer, which may be contained within the container exit VCN. The secondary VNIC may send the call to a NAT gateway, which may send the call to the public internet. In this example, the container, which may be accessible in real time by the customer, can be isolated from the control plane VCN and from other entities contained within the data plane VCN. The container may also be isolated from other customers' resources.

[0074] In another example, a customer can use a container to invoke a cloud service. In this example, the customer may execute code within a container that requests a service from the cloud service. The container can send this request to a secondary VNIC, which can send it to a NAT gateway, which can send it to the public internet. The public internet can be used to send this request to an LB subnet included in the control plane VCN via an internet gateway. In response to deciding that this request is valid, the LB subnet can send this request to an application subnet, which can send this request to the cloud service via a service gateway.

[0075] It should be understood that the IaaS architecture shown in the above diagram may include components other than those shown. Furthermore, the embodiments shown in the diagram are merely examples of cloud infrastructure systems that may incorporate embodiments of this disclosure. In some other examples, the IaaS system may include more or fewer components than those shown in the diagram, may combine two or more components, or may have different configurations or arrangements of components.

[0076] In one embodiment, the IaaS system described herein may include the provision of a set of applications, middleware, and database services that are self-service, subscription-based, elastically scalable, reliable, highly available, and securely delivered to the customer.

[0077] Cloud environment According to the embodiment, the cloud infrastructure environment may be used to provide a dedicated cloud environment, for example, as one or more private label cloud environments, for use by tenants of the cloud infrastructure environment in accessing subscription-based software products, services, or other offerings associated with the cloud infrastructure environment.

[0078] Figure 7 illustrates how the system can provide a dedicated label cloud environment or private label cloud environment for use by tenants or customers of a cloud infrastructure environment, according to the embodiment.

[0079] While the various examples described herein illustrate different systems, methods, and / or techniques that may be used in the context of providing a private label cloud (PLC) environment, according to different embodiments, the systems, methods, and techniques described herein may be used within or in conjunction with other types of cloud environments.

[0080] As shown in Figure 7, according to the embodiment, a cloud infrastructure provider can provide one or more cloud environments (e.g., PLC environments) or realms to an operator 320, for example, a customer of the cloud infrastructure acting as a reseller. The operator / reseller can then customize and extend the cloud environments for use by the customer 330 (of the operator / reseller) to use in accessing subscription-based software products, services, or other offerings associated with the cloud infrastructure environment.

[0081] For illustrative purposes, examples of such subscription-based products, services, or other offerings may include various cloud infrastructure software products, such as Oracle Fusion Applications products, or other types of products or services that allow customers to subscribe to use those products or services.

[0082] Figure 8 further illustrates the use of a cloud realm for use by a tenant or customer of a cloud infrastructure environment, according to an embodiment.

[0083] As shown in Figure 8, according to the embodiments, the system may include a cloud subscription service or component called a subscription manager in some embodiments herein, which exposes one or more subscription management APIs to onboard new customers or to create orders used to create subscriptions and to initiate workflows to coordinate billing and pricing services or other components for use with Cloud Realm 400.

[0084] According to one embodiment, when an operator (e.g., a PLC operator) or an operator's customer requests a cloud environment, the system creates realms for use within regions 402, 404, along with tenancies 416 owned by one or more providers. These tenancies enable the regions to function with the required service infrastructure and are managed by the cloud infrastructure provider.

[0085] According to one embodiment, the first step in the process is to create an operator tenancy 406 for the operator before the region and associated realms are handed over to the operator for subsequent management. The operator then becomes the administrator of this tenancy, within which the operator can view and manage everything that happens within that region, including customer accounts and the usage of cloud resources by those customers 412.

[0086] Generally, after a region is handed over to or provided to an operator, the cloud infrastructure provider cannot access the data within the operator tenancy, for example, to troubleshoot any issues that may arise, unless the operator allows the cloud infrastructure provider to access the data within the operator tenancy.

[0087] According to the embodiment, the operator can then create additional internal tenancies 408 intended for the operator's own internal use, for example, to evaluate what the end-user or customer experience will be like, or to provide sales demo tenancies, or to operate a database for the operator's own internal use. The operator can also create one or more customer tenancies 410, where the end-user or customer becomes the administrator of the customer tenancies 410. Cloud infrastructure usage, such as compute, storage, and other infrastructure resources, is aggregated by the operator reflecting both the operator's usage and the operator's customers' usage and reported to the cloud infrastructure provider.

[0088] Depending on the embodiment, a user interface or console may be provided that allows the operator to manage their customer accounts and the services provided by the customer. The cloud infrastructure provider may also use a cloud infrastructure tenancy, such as a Fusion Applications tenancy, to install any infrastructure services required for use by the operator and the operator's customers.

[0089] Figure 9 further illustrates the use of a cloud realm for use by a tenant or customer of a cloud infrastructure environment, according to an embodiment.

[0090] As shown in Figure 9, according to the embodiment, a service or component of the subscription manager 424 exposes one or more subscription management APIs to onboard new customers or to create orders used to create subscriptions and initiate workflows to coordinate billing and pricing services or other components.

[0091] According to one embodiment, the system may also include a billing service 428 or component that operates on subscription and preferred billing accounts or logical containers used to generate invoices for customers.

[0092] According to one embodiment, the system may also include a subscription pricing service (SPS) 426 or component which operates on a product catalog defining products that can be purchased by a customer and may be used to provide a price list (e.g., rate cards) which the pricing service also possesses.

[0093] According to the embodiment, products may be selected from the product hub to support the sales process in realms 420 and 422 in which subscriptions are created. After an order is created via the subscription service 430, the subscription is created in the subscription manager, which then manages the lifecycle of that subscription and provisions what needs to be provisioned in downstream services. The SPS component then manages pricing and usage aspects for use in billing the operator for final costs or in its ability to bill the customer. Usage events are forwarded to the billing service or component, an invoice is created according to the subscription billing preference, and sent to the accounts receivable component.

[0094] According to one embodiment, services provided in the realm report their usage to a metering service or component 432, but such usage is not associated with any price. The valuation process determines the cost of each specific event, for example by applying a rate card, determines the unit and cost of that subscription, associates this cost with the record, and then forwards it to the billing service or component.

[0095] As further shown in Figure 9, according to the embodiment, the operator may control multiple realms A, B, for example, an operator operating in multiple countries may want to operate a completely isolated data center for the United States and another completely isolated data center for Europe to address, for example, management or regulatory requirements. According to the embodiment, the usage associated with these multiple realms in 434 may be aggregated for use by the central subscription manager 435 and, where applicable, the prime billing service 436 in billing to the operator.

[0096] The various system examples presented above are provided to illustrate computing environments that may be used to provide a dedicated label cloud environment or private label cloud environment for use by tenants of a cloud infrastructure in accessing subscription-based software products, services, or other offerings related to the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein may be used in conjunction with other types of cloud computing environments.

[0097] Cloud Subscription Figure 10 shows an embodiment of a system for providing access to software products or services in a cloud computing environment or other computing environment.

[0098] As shown in Figure 10, according to the embodiments, the system may be provided as a cloud computing environment or other computing environment, referred to as a platform in some embodiments herein, which supports the use of subscription-based products, services, or other offerings.

[0099] Examples of such subscription-based products, services, or other offerings may include software products or services for various cloud infrastructures that allow customers to subscribe to use those products or services.

[0100] According to the embodiment, the environment may include several components provided as operator singletons 438, realm singletons 439, and regional services 440, as further described below.

[0101] Depending on the embodiment, a subscription may include artifacts such as products, commits, billing models, and states. A subscription manager service or component may expose one or more subscription management APIs to onboard new customers or to create orders used to create subscriptions and initiate workflows that coordinate the creation of appropriate footprints in billing and pricing services or components, as further described below.

[0102] According to the embodiment, the billing service or component operates on subscription and preferred billing accounts or logical containers used to generate invoices. Each billing account generates one invoice per billing cycle. The billing service includes a first pipeline that receives usage and costs from the metering service or component via a REST API, and includes a first pipeline in which billing writes usage to a database and billing workers aggregate from this database to calculate balances, and a second pipeline that receives aggregated usage and commitments and is responsible for calculating charges over billing intervals.

[0103] According to the embodiment, the Subscription Pricing Service (SPS) 426 or component operates on a product catalog that defines the products that can be purchased by a customer. The product catalog forms the backbone of a price list (i.e., rate cards) which the Pricing Service also owns. The rate cards are modeled as pricing rules on top of public list prices. The Pricing Service maintains a single price list for all products, and new product prices can be added and existing prices can be changed. The price list has a complete history, and the latest version is the current rate card. Since some contracts may require a snapshot of the rate cards to be taken, the Pricing Service handles this by recording the time when the customer's rate card was created and then querying the price list at that point in time.

[0104] According to the embodiment, the SPS or pricing service communicates with the product and pricing hub 421 and is responsible for providing information about products, the overall price list, and price lists and discounts specific to the end user or customer's subscription. For example, according to the embodiment, the SPS can synchronize product information from the product hub with the overall price list from the pricing hub.

[0105] According to the embodiment, the subscription manager service or component acts as an upstream service for receiving new order requests from the order management component 423, for example, from an Oracle Fusion Order Management environment. The subscription manager service or component can provide the SPS service with subscription information, including configured estimated time or subscription type (commitment, PayG), to help the SPS determine the effective base price (rate card) of the subscription. The subscription manager service or component can also send subscription discounts received from the order management component, which the SPS stores as entities of pricing rules.

[0106] According to the embodiment, the SPS service runs as a background process for managing the rate card service or component, which is responsible for generating rate cards for new subscriptions and updating those rate cards when new price changes occur. The SPS service can provide APIs for accessing rate cards and pricing rules. The measurement inline evaluation engine can use these APIs to retrieve rate cards and pricing rules specific to a subscription and then use this data for cost calculation.

[0107] According to the embodiment, additional SPS components may include, for example, a pricing / product hub integration component that enables an operator entity providing subscription-based products, services, or other offerings within the environment to manage product and price lists, such as those provided by a product hub and a pricing hub, respectively.

[0108] For example, in such an embodiment, the SPS product integration flow can listen for create / update events in the product hub and make calls to the SPS product API. Similarly, the SPS pricing integration flow can retrieve new price list creations from the pricing hub and call the respective SPS pricing API.

[0109] According to one embodiment, the system may also include an SPS core module that manages pricing entities and provides APIs for accessing them. Pricing entities can be accessed by internal services, such as an inline valuation engine.

[0110] According to the embodiment, the system may also include a rate card manager component. The SPS service maintains a single base price for a product at a given point in time. However, the product price for a subscription depends on the base price and price list change policy attributes at the time the subscription is estimated and configured. The SPS service uses these properties to internally maintain the prices used for subscriptions. All such price lists are grouped into rate cards. The rate card manager can create and maintain rate cards, listen for price list changes and update existing rate cards with the new prices, and listen for new subscriptions and assign rate cards based on the subscription properties.

[0111] According to the embodiment, the SPS service is responsible for managing subscription pricing rules, including discounts offered to end users or customers. Eligibility for pricing rules can be based on product attributes, such as discount groups, product categories, or specific SKUs. The SPS needs to internally identify a list of products to which these rules apply. To achieve this, a rule decoder engine can compile pricing rules in a format that allows an inline evaluation engine to use the information for cost calculations. This compilation process may occur when a product or pricing rule is created or updated.

[0112] As shown in Figure 10 as an example, according to the embodiment, in 441, product and pricing information managed in, for example, Fusion Applications is sent to the SPS component.

[0113] In step 442, the order is sent to the Subscription Manager component to create the subscription, rate card, and billing account.

[0114] In step 443, the pricing configuration and pricing rules for the new order are sent to SPS.

[0115] In version 444, the Subscription Manager component is used to configure billing accounts in the billing service or component.

[0116] In step 445, the Subscription Manager component exposes events to the Subscription Manager Streaming component.

[0117] In step 446, the billing data is sent to the accounts receivable component 425 in order to generate an invoice.

[0118] In step 447, the Subscription Manager component consumes reclaim and subscription lifecycle (RASL) events from the Subscription Manager Streaming.

[0119] At 448, Activation Service 427 reads the Subscription Manager event stream.

[0120] In step 449, the customer obtains activation data from the activation portal 429.

[0121] In 450, Tenancy Lifecycle Services 461 provision the tenancy as part of the subscription activation.

[0122] In 451, the Tenancy Lifecycle Service creates the account footprint within the account component 463 during account provisioning.

[0123] In 452, the Tenancy Lifecycle Service configures the restriction template during account provisioning within the Restriction Service 467.

[0124] In version 453, the account component functions as a downstream RASL client for handling the legacy reuse and subscription lifecycle in version 465.

[0125] In step 454, the aggregated costs and usage are sent to the billing service 428 or component.

[0126] In version 455, organizations can create child tenancies using the Tenancy Lifecycle Service.

[0127] In step 456, the measurement service 432 or component retrieves subscription mapping data.

[0128] In step 457, the subscription service 430 retrieves organizational data 469 for subscription mapping.

[0129] At step 458, the RASL component reads the subscription manager event stream.

[0130] In 459, the subscription service reads the subscription manager event stream, and in 460, the metering service or component retrieves ratecard data for each subscription, which can then be used in billing the operator or the customer for the final cost.

[0131] The above examples are provided for illustrative purposes only to illustrate computing environments that may be used to provide a dedicated label cloud environment or private label cloud environment for use by tenants of a cloud infrastructure in accessing subscription-based software products, services, or other offerings related to the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein may be used in conjunction with other types of cloud computing environments.

[0132] Console customization According to the embodiments, as described above, the described systems and methods can provide operators with cloud computing capabilities, such as through a private label cloud. These operators can provide their customers (e.g., end users) with cloud infrastructure services, including the use of a cloud console that can function as a landing platform for the operator's end customers, through such cloud computing systems and methods.

[0133] According to embodiments, the systems and methods described herein provide (e.g., to an operator) the tools necessary to customize and / or rebrand a cloud console in order to provide the ability to customize the look and feel of an instance of the cloud console. For example, tools are provided for customizing a cloud console to match a brand or theme desired by the operator. Customization may include, but is not limited to, colors, logos, or alternative product labeling.

[0134] Depending on the embodiment, the systems and methods described herein provide operators with tools to centrally manage their realms, configure how cloud services are delivered to customers (e.g., subscriptions, pricing, billing), and customize the look and feel of their console (e.g., logo, colors, branding). The systems and methods described also provide the ability to control access, manage services, display service health, and troubleshoot issues, for example, in a partnership with a cloud provider. The custom console provides a mechanism that allows operators to brand their console and centrally access tools for managing their cloud environment.

[0135] According to the embodiment, the operator console can be based on an extensible, integrated platform, similar to a cloud infrastructure console. Based on an extensible, integrated platform, cloud infrastructure providers can provide access to tools for the operator platform in the form of plug-ins, improving and guaranteeing stability for operations performed within the scope of the operator console. This delivery model also allows operators to easily develop and release their own services to customers, as they can build their own plug-ins that can be added to the operator console (e.g., after passing certain tests and stability tests), giving operators more customization and flexibility within the provided operator console.

[0136] According to the embodiment, the system and method can capture and store the operator's customized rebranding (e.g., logo, color scheme, text (e.g., copyright, terms of service, service name)) via an implemented backend that can process these customizations and store them in persistent storage, and the console can access those customizations in persistent storage. The console can retrieve from such backend storage to expose a user interface containing the operator's customizations, which are selected and configured via the console UI, when it is published / accessed.

[0137] While the various examples described herein illustrate different systems, methods, and / or techniques that may be used in the context of providing a private label cloud (PLC) environment, according to different embodiments, the systems, methods, and techniques described herein may be used within or in conjunction with other types of cloud environments.

[0138] Console architecture According to the embodiments, the user experience configuration service (referred to as the UX configuration service in some embodiments herein) may include cloud provider functionality in addition to control plane services (e.g., low-traffic services) delivered as serverless applications using APIs such as API gateways. In addition, the configuration service may be preceded by a proxy (e.g., a service platform, SPLAT proxy) which can handle certain aspects of authentication, authorization, and load balancing (e.g., authentication by one or more methods such as authentication by an authentication service, authorization by one or more methods such as authorization by an authorization process, auditing and logging, and load balancing by throttling).

[0139] In one embodiment, the API gateway may expose a public endpoint (which may not necessarily be accessible to customers) that could be called a Splat proxy. This endpoint may be protected by an authentication method (e.g., mTLS, a method for mutual authentication). To prevent attacks (e.g., DDoS), the system and methods may leverage the rate limiting capabilities provided by the API gateway. Calls to the cloud infrastructure provider's functionalities may be controlled by an internal identity and access management service or other similar service, so that only API gateways created in the configured service tenancy can call the cloud infrastructure provider's functional endpoints.

[0140] Figure 11 shows an architecture for providing console customization according to an embodiment.

[0141] As shown in Figure 11, according to the embodiment, within the cloud infrastructure environment 100, operator realms 1100 can be provided / defined that can be associated with operators of cloud infrastructure environments such as the aforementioned cloud infrastructure environment. A cloud infrastructure provider can provide one or more cloud environments (e.g., private label cloud environments) to an operator, for example, a customer acting as a reseller, and can define operator realms 1100 within those cloud environments.

[0142] According to the embodiment, there may be multiple tenancies defined within or in relation to the operator realm, such as an operator access tenancy 1101, a console configuration service tenancy 1105, a service tenancy 1108, and a customer tenancy 1113.

[0143] According to one embodiment, a user of operator 1120 from operator access tenancy 1101 can interact with operator console 1102, for example, via branding plugin user interface 1103. This could be in the form of a privately accessible website that provides, for example, options for customizing the operator's website hosted by / provided by cloud infrastructure environment 100 via branding plugin user interface.

[0144] According to the embodiment, in 1121, an operator, or an authorized user of the operator such as operator user 1120, can interact with the branding plugin within the operator console 1102, for example, via a web interface or other API.

[0145] According to the embodiment, such interaction between an operator user and a branding plugin may include processes for customizing the look and feel of the operator's space (e.g., an inbound or outbound webpage or console) hosted in a cloud infrastructure environment, such as customizing the look and feel of the customer experience 1112.

[0146] According to the embodiment, such interaction with the branding plugin may further include instructions for updating the theme of the operator's page or console, such as colors, branding, logos, trademarks, text fonts, text sizes, and color palettes. After the operator user has finished making the desired changes / updates / customizations in the branding plugin, instructions for saving these changes may be received, which can then be translated into one or more calls and passed to a configuration service. Such calls may include, for example, REST API calls.

[0147] According to one embodiment, based on the interactions and instructions received by the branding plugin from step 1121, the branding plugin can interact with configuration services, including various calls such as REST API calls. Such calls may be directed in 1122 via a proxy such as a SPLAT proxy. In one embodiment, the proxy can handle certain aspects of authentication (e.g., authentication by one or more methods, such as authentication by an authentication service), authorization (e.g., authorization by one or more methods, such as authorization by an authorization process), and load balancing (e.g., load balancing by throttling), auditing, and logging (e.g., logging of records of interactions in accessible memory).

[0148] According to one embodiment, the proxy can forward a call, such as a REST API call, to a configuration service within the configuration service tenancy. The configuration service can perform checks to determine various characteristics related to the call received from the proxy.

[0149] According to the embodiment, such checks may include, for example, whether the provided color is within the correct color range and whether the uploaded logo is the correct size. In this way, the configuration service can function as a validator for determining whether the desired input submitted by the operator user is valid for any particular page or console. The configuration service (e.g., a user experience configuration service) can generate and process configuration artifacts (e.g., user experience configuration artifacts). The configuration service may then store these artifacts in a configuration staging bucket, which may be associated with memory accessible by the configuration service. If an operator user is actively making changes, it is undesirable to publish such changes immediately after the call is received. For this reason, such changes are stored in a temporary staging bucket so that the operator user can preview the changes collectively or in batches before such changes are published.

[0150] According to the embodiment, in order to verify the validity of a custom UX configuration, for example, upon receiving an upload or other customized artifact (e.g., a brand logo) from an operator, the system can perform checks such as memory size, dimensions, non-maliciousness (e.g., not being a malicious script or HTML code), and supported file types (supported file types may include, for example, PNG or JPG format). The described system and method can perform such checks depending on the artifact in question.

[0151] For example, a branding plugin can check the dimensions and memory size of uploaded artifacts, and a UX configuration service can check for valid file types. If all checks pass but the uploaded artifact still breaks the console code, the uploaded artifact / custom artifact will not be sent to the console. The console can fall back to all or part of the general UX configuration, thereby allowing the console to continue functioning. In some embodiments, if some uploaded custom artifacts pass validation but others do not, the fallback situation may be a combination of the default / general UX configuration combined with other elements of the configured custom UX configuration.

[0152] According to one embodiment, upon receiving a request to preview changes made by an operator user to an operator's page or console, the configuration service may, based on artifacts stored in a staging bucket, transfer such artifacts from the staging bucket to a configuration preview bucket in a service tenancy, such as the origin service tenancy, in 1125. The console may then render a preview of the page or console from this preview bucket, based on the artifacts stored in the staging bucket. Such a preview may include, for example, one, some, or all of the changes / customizations made by an operator user in a branding plugin. Such a preview may be rendered in 1127 by a service (e.g., the origin service), and may be rendered, for example, as a privately accessible website for use by an operator.

[0153] According to the embodiment, the preview does not simply generate an image (displayed in the branding plugin user interface) as a console preview with the new colors selected by the operator. The preview also provides UI components and interaction with those components. The operator is provided with a dynamic way to preview changes to the console, and the operator can interact with the console plugin and UI components without actually exposing the changes.

[0154] According to one embodiment, in order to provide such generation of a live preview of the console, the service provides an API that captures identifiers for the UX configuration (UxConfig) and theme (UxTheme) that the operator wants to preview, and this API returns a path that the console can use to load the UX configuration, along with other required attributes.

[0155] According to one embodiment, when an operator user issues a command to publish a change / customization via a branding plugin, the configuration service (1126) can retrieve the artifact stored in the staging bucket and transfer such artifact to the configuration production bucket in the service tenancy. From there, the artifact is cached on the server host by the service (1128). The artifact is then provided to the end user (1130) by the service, e.g., the origin service (1129), and the end user (1130) can interact with the rendered page / console (1130).

[0156] In some embodiments, any changes to a configuration (e.g., user experience configuration) or theme (e.g., user experience theme) may affect the tenancies of all customers in the realm, so it is important for operators to preview such changes before they are published live. To support the preview function, the configuration service may maintain several separate buckets. The first two buckets may be placed in front of a service (e.g., an origin service) that can serve files from these buckets. The configuration production bucket 1110 can store all configuration and theme artifacts published by the operator. Any changes in this bucket are visible to all end customers in the console. The configuration preview bucket 1109 can store configuration and theme artifacts so that operators can preview changes before publishing them to the production bucket.

[0157] According to one embodiment, the console can read manifest files from the configuration production bucket and the configuration preview bucket (for previewing changes only), which serve as entry points for loading configurations and themes into the console. All other files and folders are references from the manifest files using relative paths, thus providing flexibility in the folder structure. The names and locations of these files are managed by a contract between the configuration service and the console.

[0158] In one embodiment, Figure 11 shows several tenancies, including an Operator Access tenancy 1101, a Console Configuration Service tenancy 1105, a Service tenancy 1108, and a Customer tenancy 1113. Of these four tenancies, two can be operated and accessed exclusively by the Cloud Infrastructure Environment Provider, namely the Console Configuration tenancy 1105 and the Service tenancy 1108. The Operator Access tenancy (referred to as OAT in some embodiments herein) may include a tenancy set up / configured by the Cloud Infrastructure Environment Provider for authorized use by operators and operator users who may be configured as administrators of the OAT. The Customer tenancy is an Operator tenancy from which the Customer can access and interact with a customized console / page of the Operator running within the Cloud Infrastructure Environment, and is transparent to the end user when accessed by the Customer (e.g., End User 1130).

[0159] Figure 12 shows multiple paths for providing console customization according to the embodiment.

[0160] As shown in Figure 12, according to the embodiment, multiple paths may be provided for providing console customization, including an operator path 1210, a console developer path 1220, and an end-user path 1240.

[0161] According to the embodiment, in the operator path 1210 (e.g., an operator in a cloud infrastructure environment, e.g., a PLC operator), one or more realm operators 1211 can use the branding plugin 1212 to define / interact with a custom user experience configuration 1213 to define a custom configuration 1214, a custom theme 1215, and a custom asset 1216. The custom configuration may include a structure such as a JSON structure, along with nested key-value pair fields. The configuration file may represent specific aspects of customization (e.g., custom strings, branded HTML metadata, feature toggle overrides, navigation registry (nav registry) overrides).

[0162] In some embodiments, the configuration file is a singleton, and a realm can only have one of several configurations. A custom theme may include special configurations that define the console's styling cues (color, font, layout). A realm can have multiple defined themes (e.g., a red theme, a blue theme). Custom assets may include, for example, images, icons, or fonts. In some embodiments, executable code (html, css, js) is not stored as an asset. Assets can be theme-independent (e.g., a favicon) or theme-specific (e.g., a colored version of a logo).

[0163] According to one embodiment, an operator can manage custom UX configurations using a branding plugin. The branding plugin can also enable the operator to upload configurations, assets, and themes to a UX configuration service. The branding plugin can give the operator the ability to preview operator changes in real time and, after review, publish operator changes to a service, such as an origin service.

[0164] According to the embodiment, these operators are permitted to publish custom user experience configurations, etc., by uploading them to the user experience configuration server 1218 in 1217 to represent the operator's branding / theme / customization within the realm (e.g., PLC realm). Such customizations may be published to services 1230, such as the origin service, in 1219.

[0165] According to the embodiment, the UX configuration service 1218 can provide functionality for custom UX configurations (e.g., CRUD (create, read, update, and delete) functionality) and enable the custom UX configuration to be exposed to a service such as the origin service so that the console can consume the custom UX configuration. Since end users do not need to interact with this service, it is accessible only to operators. Therefore, the UX configuration service can be gated / protected by authentication and authorization services, and access can be restricted to users within the operator tenancy.

[0166] According to the embodiment, the aforementioned route can support theme selection. If multiple themes are defined in the realm, the customized console can allow the operator user to select a preferred theme. The associated theme ID may be stored in the console personalization service as a user-level preference. If the user has not selected a preferred theme, or if this service is unavailable, the console falls back to the realm's default theme (for example, as set by the console developer route).

[0167] According to one embodiment, a process may be provided to populate the console with CSS (cascading style sheet) styles at runtime in order to render the console using the active theme. The console configuration service can tokenize all theme-aware CSS properties so that their values ​​can be populated at runtime. In the case of component colors, this means that the colors of all components in the console are mapped to one of a predefined palette of colors.

[0168] According to the embodiment, each defined / configured element of a custom UX configuration can be tokenized, for example, by a configuration service. Such tokenization can be used for input into a custom console and further used in debug / error checking modes.

[0169] According to one embodiment, the UX configuration service can store UX configurations (configuration and asset files) in an object store. Within this object store, the service has two private buckets: staging and production. This enables a two-stage publishing of UX configurations. In the staging bucket, the operator creates and manages drafts of the UX configuration. In the production bucket, after the operator is satisfied with the draft, a command can be received instructing the UX configuration service to publish the draft to the production bucket. A service, such as the origin service, can poll the production bucket for changes to the published custom UX configuration (e.g., at configurable intervals, such as every three minutes) and provide the custom UX configuration to all console users in the realm. A preview bucket in the service tenancy may be used to preview consoles with the staging configuration applied.

[0170] According to the embodiment, the UX configuration service can recognize / utilize two separate backend resources. These backend resources are transparent to the console, but branding plugins need to be aware of them. First, the UX configuration backend resource can represent a bundle of theme-independent common assets and configurations. This is a singleton resource, and only one active UX configuration resource can exist per realm. Second, the UxTheme backend resource can represent a bundle of theme-specific configurations (e.g., theme.json) and assets. Multiple UxTheme resources can exist, defined per realm.

[0171] According to one embodiment, via the console developer path 1220, the console team 1221 can retrieve / request a default user experience configuration 1223 in 1222, which may include a default configuration 1224, a default theme 1225, and default assets 1226. The default user experience configuration can be merged in 1227 in an artifact repository 1228, which may include a repository manager, and deployed in 1229 to a service 1230, for example, an origin service, along with custom user experience configurations provided via the operator path. This default user experience configuration can be used, for example, in non-PLC realms (e.g., realms where operator customizations are not applied) and may also be used in PLC realms as a fallback in error situations, such as when the console is unable to load a custom configuration defined by the operator.

[0172] According to the embodiment, in the end-user path 1240, when the end-user 1243 calls and loads the console 1241 (e.g., the cloud console) in 1242, the console retrieves a custom or default user experience configuration from the service 1230 (e.g., the origin service) during initialization in 1231. The console uses the retrieved user experience configuration to render a themed / branded console / page.

[0173] Figure 13 is a lifecycle diagram of backend resources for console customization according to an embodiment.

[0174] As shown in Figure 13, according to the embodiment, each backend resource (as previously described in the context of a custom UX configuration 1213 which may include a custom configuration 1214, a custom theme 1215, and a custom asset 1216) can go through the lifecycle shown in Figure 13, which is mapped to a UI operation / service API. These lifecycle states include staging buckets 1301, 1303, 1305, 1307, 1309, and 1311, as well as production buckets 1312, 1313, 1315, 1317, 1320, and 1322.

[0175] According to the embodiment, in 1302, the operator can create a new empty custom UX configuration in a staging bucket in a created state. From there, in 1304, the operator can upload a first set of configurations and assets. Next, the operator can create a new draft of the custom UX configuration by uploading, for example, further configurations and assets. The resources then become modified. The operator can create a new draft (modified state) by uploading further configurations and assets, or discard the draft. After satisfaction, the operator publishes the draft in a staging bucket or production bucket in 1306.

[0176] According to one embodiment, if the operator wishes to restart when reviewing resources in a staging bucket, the operator can re-upload the first set of configurations and assets at 1308, then edit and upload further configurations and assets, leaving the resources in a modified state again. After satisfaction, the operator can publish the draft in the staging bucket or production bucket at 1310. This cycle can be repeated, with parts of the resources being discarded at 1314, until the operator is satisfied with the resources, at which point the resources can be published to the production bucket.

[0177] According to the embodiment, the lifecycle further supports private 1318, which removes a publicly exposed custom UX configuration from a production bucket and removes the file from a service, such as the origin service. Private also reverts the custom UX configuration to a draft (modified) state in the staging bucket, but does not delete the custom UX configuration from the system. The operator can still access the draft if needed. Finally, delete 1321 removes the custom UX configuration from the system. To ensure that the operator does not accidentally delete a publicly exposed (available to end users) custom UX configuration, the delete operation can only occur from the created lifecycle state, while discard 1319 can occur from the modified state.

[0178] According to the embodiment, the lifecycle state transitions shown and described in the figure support multiple functions, including enabling updates to already published UX configurations / UX themes, and preventing the deletion of published UX configurations / UX themes in a single step, as deletion could be accidentally triggered and break console functionality for all end users in that realm.

[0179] Figure 14 shows a user interface for console customization according to an embodiment.

[0180] As shown in Figure 14, according to the embodiment, a user interface 1400, such as one generated by a branding user interface for console customization, may include multiple components, including an image section 1410 and a color section 1420, the color section being divided into different sections including a general color 1430 and a header / footer color 1440.

[0181] According to one embodiment, within the image section, the operator user may upload various assets, such as logos and images used in browser tabs, as shown in the shown embodiment. Such assets can then be added, for example, to a custom UX configuration resource, which can be used to publish the live preview 1450, as previously described.

[0182] According to one embodiment, a color section 1420 may be displayed, allowing the operator user to select a limited number of colors to be used in a customized console, including general colors 1430 and header and footer colors 1440. From these colors, the branding UI can generate a palette to be used within the operator's customized console using a palette generator (described below in the context of Figure 17). Such an asset can then be added, for example, to a custom UX configuration resource, which can be used to publish a live preview 1450, as previously mentioned.

[0183] According to one embodiment, the UI 1400 further includes a review and publish button 1460, which allows an operator user to save selected resources on a custom branding page to a custom UX configuration resource, which can then be published via a service such as an origin service upon successful completion.

[0184] Figure 15 shows a user interface for console customization according to an embodiment.

[0185] As shown in Figure 15, according to the embodiment, a user interface 1500, such as that generated by a branding user interface for console customization, may include multiple components, including an image section 1510 and a color section 1520, the color section being divided into different sections including general colors 1530, header / footer colors 1540, primary button colors 1550, and secondary button colors 1560.

[0186] According to one embodiment, within the image section, the operator user may upload various assets, such as logos and images used in browser tabs, as shown in the indicated embodiment. Such assets can then be added, for example, to a custom UX configuration resource, which can be used to publish the live preview 1570, as previously described.

[0187] According to one embodiment, a color section 1520 may be displayed, allowing the operator user to select a limited number of colors to be used in a customized console, including a general color 1530, a header and footer color 1540, a primary button color 1550, and a secondary button color 1560. From these colors, the branding UI can generate a palette to be used within the operator's customized console using a palette generator (described below in the context of Figure 17). Such an asset can then be added, for example, to a custom UX configuration resource, which can be used to publish a live preview 1570, as previously mentioned.

[0188] According to one embodiment, the UI 1500 further includes a review and publish button 1580, which allows an operator user to save selected resources on a custom branding page to a custom UX configuration resource, which can then be published via a service such as an origin service upon successful completion.

[0189] Figure 16 shows a user interface for console customization according to an embodiment.

[0190] As shown in Figure 16, according to the embodiment, a user interface 1600, such as one generated by a branding user interface for console customization, may include multiple components, including a homepage promotion section 1610 which includes a text section 1620.

[0191] According to one embodiment, within the homepage promotion section 1610, an operator user may specify a portion of the console using, for example, a dropdown menu or other selection, where text can be entered from the text section 1620 and the text can be formatted. Information from the homepage promotion section, as well as text entered in the text field 1620, can be used, for example, to generate or modify custom UX configuration resources.

[0192] According to one embodiment, the UI 1500 further includes a live preview window 1630 that can display a live preview of a customized console, as well as review and publish buttons 1640 that allow an operator user to save selected resources on a custom branding page to a custom UX configuration resource, which can be published via a service such as an origin service upon successful completion.

[0193] Figure 17 shows the color space used for generating custom palettes for console customization according to the embodiment.

[0194] As shown in Figure 17, according to the embodiments described above, a custom console for operators, such as operators in a PLC environment, can be generated. Such a custom console may include, for example, a custom logo (e.g., the operator's logo), as well as drawing the console with custom colors and a customized color palette that can be applied to the header, footer, navigation menu, background, accents, or link colors.

[0195] According to one embodiment, custom palette generation can begin by having an operator user select a limited set of reference colors (e.g., seven colors) to be used in the generated custom console. These reference colors may be defined, for example, by a branding plugin. From these reference colors, the branding plugin can generate a color palette scaled by saturation and brightness to produce all the colors that may be used in the custom console. Such custom palette generation improves computational efficiency.

[0196] According to one embodiment, using the Hue-Saturation-Luminance color space 1700, and given a limited set of reference colors as defined by the operator user, the branding plugin can generate a custom palette for use by the operator user in designing and customizing the console. For example, by inputting seven reference colors, the custom palette generator can generate over 50 unique colors to be used within the operator's custom console. This enables consistency and reduces the overhead for developers and designers in tracking and mapping dozens of unique colors.

[0197] According to one embodiment, the system can utilize the HCL (Hue-Saturation-Luminance) color space for palette generation. This color space may include a cylindrical color space specifically designed to ensure that scaled colors are perceptually similar. Standard RGB and HSL color spaces do not support perceptual mapping and are therefore unsuitable for palette generation.

[0198] Figure 18 is a flowchart of a method for generating a customizable console according to an embodiment.

[0199] As shown in Figure 18, according to the embodiment, this method can provide a computer equipped with a microprocessor as part of a cloud infrastructure environment in step 1810.

[0200] According to one embodiment, this method can provide a customizable console in a cloud environment in step 1820, the customizable console providing access to subscription-based products, services, and other offerings.

[0201] According to one embodiment, this method can provide access to a customizable console in the context of a cloud environment in step 1830.

[0202] According to one embodiment, this method allows a customizable console to be customized via a configuration service by a first entity associated with a first tenancy of a cloud environment in step 1840, the configuration service generates console configuration resources in response to instructions received from the first entity associated with the first tenancy, and the generated console configuration resources are used to customize the customizable console when access to the customizable console is provided.

[0203] According to one embodiment, the generated console configuration resources may be stored in a first storage location.

[0204] According to one embodiment, the first storage location may include preview storage. Based on the generated console configuration resources stored in the preview storage location, a live preview of the console is generated for use within the console configuration user interface.

[0205] According to one embodiment, this method can tokenize the generated console configuration resources before they are stored in a first storage location and a second storage location.

[0206] According to one embodiment, the received instruction may include a set of colors selected for use within a customizable console. Based on the received instruction, this method can generate a color palette containing multiple colors for use within a customizable console, the color palette containing colors that have a perceptual similarity to the set of colors.

[0207] According to one embodiment, this method can tokenize each of the multiple colors in the generated color palette.

[0208] According to one embodiment, further instructions may be received to publish a customizable console. Upon receipt of such instructions, the generated console configuration resources may be stored in a second storage location, which includes production storage. A live version of the customizable console may be generated by polling the storage location to discover the generated console configuration resources stored therein. Such a live version may be made accessible to customers in a cloud environment.

[0209] According to the embodiment, the generated console configuration resource can follow a lifecycle that supports creation, modification, deletion, and unpublishing.

[0210] According to one embodiment, before the configuration service receives the command, the command may be received by a proxy. The proxy can then perform at least one authentication, authorization, auditing, and load balancing.

[0211] According to the embodiment, the received command can be received from a first tenancy in the cloud environment, and the first tenancy is associated with a first identity provider. The configuration service can be associated with a second tenancy in the cloud environment, and the second tenancy is associated with a second identity provider.

[0212] Customizable console debug mode According to embodiments, the systems and methods described herein can support a debugging mode (also referred to herein as “debug mode”) for a customizable console. The debug mode may include systems and methods for determining whether all parts of the custom UX configuration resources of the customized console are valid for generating the customized console. Such a debug mode enables the easy detection and identification of bugs or errors in the custom UX configuration and enables the determination of whether such a customized console can be generated without errors, given that it is based on the custom UX configuration resources.

[0213] According to one embodiment, the debug mode can generate a modified version of the customized console preview based on a custom UX configuration resource, for example, via a debug service. This modified version of the customized console preview can be generated in a way that allows for easy detection of parts or sections of the customized console that are correctly configured (e.g., correctly tokenized) and parts or sections that are incorrectly configured (e.g., not tokenized or causing the console to fail when attempting to render), for example, when displayed through the user interface.

[0214] According to one embodiment, in which a debugging service generates a modified version of a preview of a customized console, the customized console may be generated with a color palette generated using bright, saturated hues (such a color palette is not typically based on a color palette selected and generated for the operator, and is generated to have clear color differences between parts of the modified version of the preview so that parts of the preview can be quickly identified).

[0215] Next, in generating the modified version of the preview, the debugging service can color any tokenized elements of the customized console, and elements configured to draw without errors, with a color from the generated color palette. Any non-tokenized elements of the modified preview can be generated with a different characteristic color from the color palette to provide easy visual detection of parts of the customized console that are not tokenized or otherwise draw errors in the customized console, or otherwise cause the customized console not to draw for display by customers in the cloud infrastructure environment.

[0216] According to one embodiment, debug mode may be run before custom UX configuration resources are saved to the production bucket, thereby conserving computing resources and making the system more efficient.

[0217] Figure 19 shows an architecture for providing a debug mode for console customization according to an embodiment.

[0218] As shown in Figure 19, according to the embodiment, within the cloud infrastructure environment 100, operator realms 1100 can be provided / defined that can be associated with operators of cloud infrastructure environments such as the aforementioned cloud infrastructure environment. A cloud infrastructure provider (e.g., Oracle Cloud Infrastructure, OCI) can provide one or more cloud computing environments, such as private label cloud environments, to OCI customers acting as operators, such as resellers, and can define operator realms 1100 within those cloud computing environments.

[0219] According to one embodiment, there may be multiple tenancies defined within or in relation to the operator realm, such as operator access tenancy 1101, console configuration service tenancy 1105, service tenancy 1108, and customer tenancy 1113.

[0220] According to one embodiment, a user of operator 1120 from operator access tenancy 1101 can interact with operator console 1102, for example, via branding plugin user interface 1103. This could take the form of a privately accessible website that provides, for example, options for customizing the operator's website hosted in / provided by cloud infrastructure environment 100 via branding plugin user interface.

[0221] According to the embodiment, in 1121, an operator, or an authorized user of the operator such as operator user 1120, can interact with the branding plugin within the operator console 1102, for example, via a web interface or other API.

[0222] According to the embodiment, such interaction between an operator user and a branding plugin may include processes for customizing the look and feel of the operator's space (e.g., an inbound or outbound webpage or console) hosted in a cloud infrastructure environment, such as customizing the look and feel of the customer experience 1112.

[0223] According to the embodiment, such interaction with the branding plugin may further include instructions for updating the theme of the operator's page or console, such as colors, branding, logos, trademarks, text fonts, text sizes, and color palettes. After the operator user has finished making the desired changes / updates / customizations in the branding plugin, instructions for saving these changes may be received, which can then be translated into one or more calls and passed to a configuration service. Such calls may include, for example, REST API calls.

[0224] According to one embodiment, based on the interactions and instructions received by the branding plugin from step 1121, the branding plugin can interact with configuration services, including various calls such as REST API calls. Such calls may be directed in 1122 via a proxy such as a SPLAT proxy. In one embodiment, the proxy can handle certain aspects of authentication (e.g., authentication by one or more methods, such as authentication by an authentication service), authorization (e.g., authorization by one or more methods, such as authorization by an authorization process), and load balancing (e.g., load balancing by throttling), auditing, and logging (e.g., logging of records of interactions in accessible memory).

[0225] According to one embodiment, the proxy can forward a call, such as a REST API call, to a configuration service within the configuration service tenancy. The configuration service can perform checks to determine various characteristics related to the call received from the proxy.

[0226] According to the embodiment, such checks may include, for example, whether the provided color is within the correct color range and whether the uploaded logo is the correct size. In this way, the configuration service can function as a validator for determining whether the desired input submitted by the operator user is valid for any particular page or console. The configuration service (e.g., a user experience configuration service) can generate and process configuration artifacts (e.g., user experience configuration artifacts). The configuration service can then store these artifacts in a configuration staging bucket, which may be associated with memory accessible by the configuration service.

[0227] If an operator user is actively making changes, it is undesirable to publish such changes immediately after the call is received. Therefore, such changes are stored in a temporary staging bucket so that the operator user can preview them all at once or in batches before they are published.

[0228] According to the embodiment, in order to verify the validity of a custom UX configuration, for example, upon receiving an upload or other customized artifact (e.g., a brand logo) from an operator, the system can perform checks such as memory size, dimensions, non-maliciousness (e.g., not being a malicious script or HTML code), and supported file types (supported file types may include, for example, PNG or JPG format). The described system and method can perform such checks depending on the artifact in question.

[0229] For example, a branding plugin can check the dimensions and memory size of uploaded artifacts, and a UX configuration service can check for valid file types. Finally, even if all checks pass, if the uploaded artifact still breaks the console code, the uploaded artifact / custom artifact will not be sent to the console. The console can fall back to all or part of a general UX configuration, thereby ensuring the console continues to function.

[0230] In some embodiments, if some uploaded custom artifacts pass validation but others do not, the fallback situation may be a combination of the default / general UX configuration combined with other elements of the configured custom UX configuration.

[0231] According to one embodiment, upon receiving a request to preview changes made by an operator user to an operator's page or console, the configuration service may, based on artifacts stored in a staging bucket, transfer such artifacts from the staging bucket to a configuration preview bucket in a service tenancy, such as the origin service tenancy, in 1125. The console may then render a preview of the page or console from this preview bucket, based on the artifacts stored in the staging bucket. Such a preview may include, for example, one, some, or all of the changes / customizations made by an operator user in a branding plugin. Such a preview may be rendered in 1127 by a service (e.g., the origin service), and may be rendered, for example, as a privately accessible website for use by an operator.

[0232] According to the embodiment, the preview does not simply generate an image (displayed in the branding plugin user interface) as a console preview with the new colors selected by the operator. The preview also provides UI components and interaction with those components. The operator is provided with a dynamic way to preview changes to the console, and the operator can interact with the console plugin and UI components without actually exposing the changes.

[0233] According to one embodiment, in order to provide such generation of a live preview of the console, the service provides an API that captures identifiers for the UX configuration (UxConfig) and theme (UxTheme) that the operator wants to preview, and this API returns a path that the console can use to load the UX configuration, along with other required attributes.

[0234] According to one embodiment, when an operator user issues a command to publish a change / customization via a branding plugin, the configuration service (1126) can retrieve the artifact stored in the staging bucket and transfer such artifact to the configuration production bucket in the service tenancy. From there, the artifact is cached by the service on the server host (1128). The artifact is then provided to the end user (1130) by the service, e.g., the origin service (1129), and the end user (1130) can interact with the rendered page / console (1130).

[0235] In some embodiments, any changes to a configuration (e.g., user experience configuration) or theme (e.g., user experience theme) may affect the tenancies of all customers in the realm, so it is important for operators to preview such changes before they are published live. To support the preview function, the configuration service may maintain three separate buckets. The first two buckets may be placed in front of a service (e.g., an origin service) that can serve files from these buckets. The configuration production bucket 1110 can store all configuration and theme artifacts published by the operator. Any changes in this bucket are visible to all end customers in the console. The configuration preview bucket 1109 can store configuration and theme artifacts so that operators can preview changes before publishing them to the production bucket.

[0236] According to one embodiment, the console can read manifest files from the configuration production bucket and the configuration preview bucket (for previewing changes only), which serve as entry points for loading configurations and themes into the console. All other files and folders are references from the manifest files using relative paths, thus providing flexibility in the folder structure. The names and locations of these files are managed by a contract between the configuration service and the console.

[0237] According to the embodiment, the debugging service 1905 can be provided within a cloud infrastructure environment, and this debugging service can interact with the staging bucket to generate a modified preview of the customized console for use in quickly identifying errors or potential errors that occur when / when a customized console is generated based on custom UX configuration resources stored in the staging bucket. As mentioned above, the debugging service can generate a modified preview that is displayed via the user interface based on its interaction with the staging bucket (or another bucket such as the preview bucket or the production bucket).

[0238] According to one embodiment, in which a debugging service generates a modified version of a preview of a customized console, the customized console may be generated with a color palette generated using bright, saturated hues (such a color palette is not typically based on a color palette selected and generated for the operator, and is generated to have clear color differences between parts of the modified version of the preview so that parts of the preview can be quickly identified).

[0239] Next, in generating the modified version of the preview, the debugging service can color any tokenized elements of the customized console, and elements configured to draw without errors, with a color from the generated color palette. Any non-tokenized elements of the modified preview can be generated with a different characteristic color from the color palette to provide easy visual detection of parts of the customized console that are not tokenized or otherwise draw errors in the customized console, or otherwise cause the customized console not to draw for display by customers in the cloud infrastructure environment.

[0240] According to the embodiment, Figure 19 shows several tenancies, including an operator access tenancy 1101, a console configuration service tenancy 1105, a service tenancy 1108, and a customer tenancy 1113. Of these four tenancies, two can be operated and accessed exclusively by the cloud infrastructure environment provider, namely the console configuration tenancy 1105 and the service tenancy 1108. An operator access tenancy (OAT) may include a tenancy set up / configured by the cloud infrastructure environment provider for authorized use by operators and operator users who may be configured as administrators of the OAT. A customer tenancy is an operator tenancy in which the customer can access and interact with a customized console / page of the operator running within the cloud infrastructure environment, and is transparent to the end user when accessed by the customer (e.g., an end user 1130).

[0241] According to one embodiment, the debugging service may be provided in a tenancy situation that is exclusively owned and operated by a cloud infrastructure provider.

[0242] Figure 20 shows a screenshot of the debug mode according to the embodiment. According to one embodiment, the debug service can generate a modified preview 2000 of the console based on a custom UX configuration resource, such as one set by the operator or one of their users, as generated in the graphical user interface 166.

[0243] According to the embodiment, as shown in the various shades of the figure, the properly configured and tokenized portions of the console 2010 may be drawn in a hue of a generated palette that indicates that those portions of the console are properly configured and tokenized.

[0244] According to the embodiment, as shown in the various shades in the figure, misconfigured and / or untokenized portions of the console 2020 may be drawn in a hue from the generated palette that indicates that those portions of the console are misconfigured or untokenized.

[0245] According to the embodiment, based on this modified rendering of the customized console, various parts of the custom UX configuration resource can then be quickly identified as not tokenized or incorrectly configured. In such cases, error resolution can then be handled before the custom UX configuration resource is transferred to the production bucket, as such errors or non-tokenized artifacts may result in the console being rendered incorrectly for the user below, or even defaulting entirely or partially to a generic user interface.

[0246] Figure 21 is a flowchart of a method for console debugging mode for a custom console according to an embodiment.

[0247] According to one embodiment, this method can provide a computer equipped with a microprocessor in step 2110.

[0248] According to one embodiment, this method can provide a customizable console in a cloud environment in step 2120, the customizable console providing access to subscription-based products, services, and other offerings.

[0249] According to one embodiment, this method allows a customizable console to be customized via a configuration service in step 2130, the configuration service generates console configuration resources in response to an incoming command.

[0250] According to one embodiment, this method can generate a modified preview of a console containing multiple console elements based on the generated console configuration resource in step 2140, for use in debugging the generated console configuration resource from the staging area.

[0251] According to one embodiment, generating a modified preview of the console may include generating a color palette for use in the modified preview, the color palette comprising multiple colors having high saturation.

[0252] According to one embodiment, a first set of multiple colors may be used in a modified preview to indicate a first set of console elements corresponding to tokenized assets within a generated console configuration resource.

[0253] According to one embodiment, a second set of multiple colors may be used in the modified preview to indicate a second set of console elements corresponding to untokenized assets within the generated console configuration resource.

[0254] According to one embodiment, the first set of console elements may differ from the second set of console elements.

[0255] According to one embodiment, the modified preview may be generated by a debugging service running in the context of a first tenancy in the cloud infrastructure environment.

[0256] According to the embodiment, the received command may be received from the second tenancy situation of the cloud infrastructure environment.

[0257] According to the embodiment, a first tenancy may be associated with a first identity provider, and a second tenancy may be associated with a second identity provider.

[0258] According to various embodiments, the teachings herein may be implemented using one or more computers, computing devices, machines, or microprocessors, including one or more processors, memory, and / or computer-readable storage media, programmed in accordance with the teachings herein. Appropriate software coding can be readily prepared by a skilled programmer based on the teachings herein, as will be apparent to those skilled in the art of software technology.

[0259] In some embodiments, the teachings herein may include a computer program product which is a non-temporary computer-readable storage medium containing instructions that can be used to program a computer to perform any of the processes of these teachings. Examples of such storage media may include, but are not limited to, hard disk drives, hard disks, fixed disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, or other types of storage media or devices suitable for non-temporary storage of instructions and / or data.

[0260] The foregoing description is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit the scope of protection to the exact form disclosed. Further modifications and variations will be apparent to those skilled in the art.

[0261] The embodiments have been selected and described to best illustrate the teaching principles and their practical application herein, thereby enabling those skilled in the art to understand the various embodiments, along with various modifications suitable for specific intended uses. This scope is intended to be defined by the following claims and their equivalents.

Claims

1. It is a method, To provide a computer equipped with a microprocessor, This includes providing a customizable console in a cloud environment, the customizable console providing access to subscription-based products, services, and other offerings. The method provides access to the customizable console in the cloud environment, A method further comprising a first entity associated with a first tenancy of the cloud environment customizing the customizable console via a configuration service, wherein the configuration service generates console configuration resources in response to instructions received from the first entity associated with the first tenancy, and the generated console configuration resources are used in customizing the customizable console when access to the customizable console is provided.

2. The method according to claim 1, further comprising storing the generated console configuration resources in a first storage location.

3. The first storage location includes preview storage, The method according to claim 2, wherein a live preview of the console is generated for use within the console configuration user interface based on the generated console configuration resources stored in the preview storage location.

4. The method according to claim 2, further comprising tokenizing the generated console configuration resources before they are stored in the first storage location and the second storage location.

5. The received command consists of a selected set of colors for use within the customizable console, and the method is The method according to claim 1, further comprising generating a color palette containing multiple colors for use in the customizable console based on the received command, wherein the color palette contains colors having perceptual similarity to the set of colors.

6. The method according to claim 5, further comprising tokenizing each of the plurality of colors of the generated color palette.

7. The method includes receiving further instructions to expose the customizable console, The method further includes storing the generated console configuration resources in a second storage location, wherein the second storage location includes production storage. The method according to claim 6, further comprising generating a live version of the customizable console by polling the storage location to detect the generated console configuration resources stored therein.

8. The method according to claim 7, wherein the live console is accessible to customers in the cloud environment.

9. The method according to claim 1, wherein the generated console configuration resource follows a lifecycle that supports creation, modification, deletion, and making private.

10. Before the command is received by the aforementioned configuration service, the command is received by a proxy, The method according to claim 1, wherein the proxy performs at least one authentication, authorization, auditing, and load balancing.

11. The received command is received from the first tenancy of the cloud environment, and the first tenancy is associated with the first identity provider. The method according to claim 1, wherein the configuration service is associated with a second tenancy of the cloud environment, and the second tenancy is associated with a second identity provider.

12. A system comprising a computer equipped with a microprocessor, The aforementioned microprocessor is This includes providing a customizable console in a cloud environment, the customizable console providing access to subscription-based products, services, and other offerings. To provide access to the customizable console in the aforementioned cloud environment, A system that performs a method further comprising customizing the customizable console via a configuration service by a first entity associated with a first tenancy of the cloud environment, wherein the configuration service generates console configuration resources in response to instructions received from the first entity associated with the first tenancy, and the generated console configuration resources are used in customizing the customizable console when access to the customizable console is provided.

13. The aforementioned method, The system according to claim 12, further comprising storing the generated console configuration resources in a first storage location.

14. The first storage location includes preview storage, The system according to claim 13, wherein a live preview of the console is generated for use within the console configuration user interface based on the generated console configuration resources stored in the preview storage location.

15. The aforementioned method, The system according to claim 14, further comprising tokenizing the generated console configuration resources before they are stored in the first storage location and the second storage location.

16. The received command consists of a selected set of colors for use within the customizable console. The aforementioned method, The system according to claim 12, further comprising generating a color palette containing multiple colors for use in the customizable console based on the received command, wherein the color palette contains colors having perceptual similarity to the set of colors.

17. The aforementioned method, The system according to claim 16, further comprising tokenizing each of the plurality of colors of the generated color palette.

18. The aforementioned method, Receiving further instructions to expose the aforementioned customizable console, The method further includes storing the generated console configuration resources in a second storage location, wherein the second storage location includes production storage. The system according to claim 17, further comprising generating a live version of the customizable console by polling the storage location and detecting the generated console configuration resources stored therein.

19. The system according to claim 18, wherein the live console is accessible to customers in the cloud environment.

20. The system according to claim 12, wherein the generated console configuration resource follows a lifecycle that supports creation, modification, deletion, and non-publication.

21. Before the command is received by the aforementioned configuration service, the command is received by a proxy, The system according to claim 12, wherein the proxy performs at least one authentication, authorization, auditing, and load balancing.

22. The received command is received from the first tenancy of the cloud environment, and the first tenancy is associated with the first identity provider. The system according to claim 12, wherein the configuration service is associated with a second tenancy of the cloud environment, and the second tenancy is associated with a second identity provider.

23. A non-temporary computer-readable storage medium containing instructions, wherein, when read and executed, the instructions cause a computer to perform steps, and the steps are: This includes providing a customizable console in a cloud environment, the customizable console providing access to subscription-based products, services, and other offerings. To provide access to the customizable console in the aforementioned cloud environment, The present invention further includes a first entity associated with a first tenancy of the cloud environment customizing the customizable console via a configuration service, wherein the configuration service generates console configuration resources in response to instructions received from the first entity associated with the first tenancy, and the generated console configuration resources are used in customizing the customizable console when access to the customizable console is provided, on a non-temporary computer-readable storage medium.