Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Admission controller" patented technology

Service grid stability guarantee method and device

PendingCN120200913ATransmissionAdmission controllerDistributed computing
The invention discloses a service grid stability guarantee method and device, and belongs to the technical field of computers. The method comprises the following steps: creating a service grid version management rule based on a self-defined resource definition mechanism of Kubernetes, and declaring a binding relationship between a target Deployment and a side vehicle agent version; intercepting a Pod creation request through an access controller of Kubernetes, and triggering an injection process of a service grid control plane; the service grid control plane judges whether the Pod is associated with the target Deployment or not by analyzing the label of the Deployment to which the Pod belongs; and if the Pod is associated with the target Deployment, injecting the side vehicle agent of the corresponding version into the Pod. According to the invention, the version of the service grid can still be finely controlled under the condition that the service and the service grid are deployed and decoupled, so that the service container and the verified service grid version are always deployed together; and the self-healing of the service grid and the capability that the user can autonomously and emergently exit the service grid are realized under the condition of not influencing the service.
Owner:JIANGSU SECURITIES

Resource deployment management method and system

PendingCN121541975ASoftware simulation/interpretation/emulationAdmission controllerVerification
The invention discloses a resource deployment management method and system, and the method comprises the steps: obtaining a resource deployment request submitted by a user, and the resource deployment request comprises configuration data; calling an access controller to perform global verification on the resource deployment request; if the resource deployment request passes the global verification, generating a deployment instruction based on the configuration data; a deployment instruction is sent to the resource deployment platform, so that the resource deployment platform deploys a corresponding operation unit, and the operation unit is injected into the auxiliary container meeting the requirement condition of the configuration data. According to the scheme, all the resource deployment requests are uniformly managed through the access controller, the corresponding deployment instructions can be generated for deployment only after the resource deployment requests pass the global verification, and compared with a traditional scheme, the number of access control assemblies in the system is remarkably reduced, and the resource deployment efficiency is improved. And meanwhile, the global verification can avoid the problem of resource deployment conflict possibly caused by separate realization of different functions in the traditional scheme.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

Method and system for modifying and validating API requests

Some embodiments of the invention provide a method of modifying and validating API requests received at an API server. At a mutating admission controller of the API server, the method intercepts an API request received at the API server. The method invokes a mutating webhook to query a policy agent that includes a set of policies for modifying API requests. When the policy agent determines that the API request requires modifications based on an identified policy, the method performs the modifications and forwards the modified API request for validation by the API server. After validating the API request, the method intercepts the API request at a validating admission controller and invokes a validating webhook to query the policy agent to determine whether the API request is valid. When the policy agent determines that the API request is valid, the method forwards the API request to be admitted to a database.
Owner:APPLE INC

JAVA agent version control method and system, electronic device, storage medium, and program product

PCT designated stageWO2026174928A1Node clusteringJava
Embodiments of the present disclosure provide a Java agent version control method and system, an electronic device, a storage medium, and a program product. In application deployment scenarios such as application creation or application upgrade, a master node in a container orchestration platform updates, by means of an interface server, a download address of a target-version Java agent package corresponding to instances into resource configuration information of the instances, so as to ensure that a correct Java agent version can be loaded on the basis of the download address of the Java agent package when each instance is created. An admission controller in a worker node cluster dynamically determines, on the basis of a grayscale release ratio of a new-version Java agent, a download address of a target-version Java agent package required for an instance to be created, wherein the target version can be a new version or an old version; and then, some instances of an application are controlled to load the new-version Java agent, rather than enabling all the instances of the application to load the new-version Java agent simultaneously. Thus, instance-level precise control over Java agent versions is provided, thereby improving the stability of Java agents during version upgrade.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

An isolation and security system for use in multi-tenant container orchestration

PCT designated stageWO2026147379A1Data integrityEngineering
The invention relates to an isolation and security system running on a server for use in multi-tenant container orchestration. The system of the invention aims to improve security and efficiency by providing isolated network, storage, and control plane environments for each tenant on multi-tenant container orchestration platforms. In this context, network isolation is achieved by using tenant-specific network overlay protocols, unique VXLAN Network Identifier (VNI), distributed routing mechanisms and network policy engine. Complete storage isolation and performance continuity are ensured through separate storage pools, encryption keys, and a storage QoS manager, for each tenant. Control plane isolation is supported by tenant-specific schedulers, admission controllers, and API endpoints, thus, an independent and secure management is offered. Tenant management processes are made efficient with automatic onboarding, dynamic resource allocation, and isolation verifier, and security is guaranteed. Isolated monitoring and log management are carried out with metric aggregators, log managers and anomaly detection engines, and the data integrity and security are guaranteed throughout the system in line with the principle of zero trust architecture.
Owner:BTS KURUMSAL BİLİŞİM TEKNOLOJİLERİ ANONİM ŞİRKETİ

Techniques for contextually applying a security policy on a software container

A system and method for applying a cybersecurity contextual policy in a computing environment are disclosed. In an embodiment, the method includes: detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment; detecting a policy of the computing environment, the policy including a conditional rule; generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
Owner:WIZ INC

Apparatus and method for policy-based automated exception handling

To configure an application platform for policy-based automated exception handling, a plurality of policies are established, each defining a requirement for applications. A plurality of exceptions are also established, each defining an expiration time and indicating at least one of the policies. A processor automatically generates a configuration file associating each of the exceptions with each policy indicated in the exception. The processor then automatically configures the application platform according to the configuration file. As a result of this configuration, an admission controller of the platform selectively tests an application designated for deployment to the application platform, based on a determination whether an exception assigned to the application is presently applicable to the policy. The exception is presently applicable based on an association of the exception with the policy in the configuration file, and a comparison of a present time with the exception's expiration time.
Owner:RAKUTEN MOBILE INC +1