Unified Cloud Agent Lifecycle Control Across Platform Types
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud customers and providers face challenges in managing the lifecycle of software agents installed on customer-owned compute instances due to limited access and visibility, necessitating a method for efficient agent inventory management and lifecycle control across diverse platform types and versions.
Innovation Solution
An agent management service in a provider-owned tenancy manages agent inventory and lifecycle operations, including installation, updating, and uninstallation of agents across multiple compute instances with different platform types, using a unified plugin and data plane system to facilitate secure and efficient agent deployment and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If provider-owned services participate in agent lifecycle management, then security posture is improved, but access complexity increases due to limited access to customer-owned compute instances
Solution Approach 1:
The patent introduces an agent management service as an intermediary component that operates within the customer tenancy to coordinate agent lifecycle management between the cloud provider and customer-owned compute instances. This mediator enables security monitoring and agent management functions without requiring direct provider access to customer instances, thus improving security posture while managing access complexity through a controlled intermediary layer
2Loss of information
If agents are installed on multiple customer-owned compute instances, then visibility into cloud infrastructure is improved, but operational overhead increases due to installation, updating, and uninstallation management
Solution Approach 1:
The patent implements a self-service mechanism where the agent management service automatically handles agent installation, updates, and uninstallation across multiple compute instances. The service discovers compute instances, determines agent requirements, and performs lifecycle operations autonomously without manual intervention, thereby maintaining comprehensive infrastructure visibility while significantly reducing operational overhead through automated self-management
Solution Approach 2:
The system performs preliminary actions by pre-configuring agent management policies and instance discovery mechanisms before agents need to be deployed. The agent management service proactively identifies compute instances that require agents and prepares deployment configurations in advance, enabling automated lifecycle management that reduces operational overhead while maintaining continuous infrastructure visibility
3Adaptability or versatility
If multiple agents with different platform types are deployed, then adaptability to diverse compute instances is improved, but device complexity increases due to managing different platform types and versions
Solution Approach 1:
The patent implements a universal agent management service that handles multiple platform types (Windows, Linux, macOS) and agent versions through a single unified system. The service discovers compute instances, identifies their platform types, and automatically selects and deploys appropriate agent versions, thereby achieving broad adaptability across diverse compute instances while reducing the complexity of managing multiple platforms through a unified multi-functional management interface
Data Source
AI summary
A unified security agent manager plugin within a virtual machine compute instance manages at least one agent installed within the compute instance of a cloud environment. The plugin periodically receives agent inventory information, where the agent inventory information identifies (i) a plurality of platform types of the agent, and (ii) for each platform type, one or more deployable versions of the agent. The plugin selects a platform type from the plurality of platform types. The plugin compares the one or more deployable versions corresponding to the selected platform type with a version of the agent currently installed in the compute instance. If the version currently installed in the compute instance is older than the one or more deployable versions, the plugin fetches an agent object corresponding to a deployable version from an object storage repository, and updates the version currently installed in the compute instance to the fetched deployable version.


