Cross-Tenancy Container Resource Association With Subnet Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing container orchestration systems face challenges in managing and securing the deployment and management of containerized applications across different environments, particularly in large-scale applications, and there is a need for improved security and isolation of network resources in cloud computing infrastructure.
Innovation Solution
A virtual agent executes on a virtual node within a container orchestration system, utilizing a Resource Principal Session Token (RPST) to determine subnet matching and enforce policies for request validation, ensuring secure communication and resource management between control and data planes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If container orchestration systems allow cross-tenancy resource deployment, then resource utilization and scalability are improved, but security and isolation between different tenants deteriorate
Solution Approach 1:
The patent segments network resources by assigning specific subnets to different virtual agents and their associated container instances. This segmentation isolates network traffic between tenants while allowing controlled cross-tenancy deployment, resolving the contradiction between resource scalability and security isolation.
Solution Approach 2:
The patent introduces subnet matching as an intermediary mechanism that validates and controls communication between virtual agents and container instances across different tenancies. This intermediary layer enables secure cross-tenancy resource association while maintaining isolation boundaries.
2Productivity
If network resources are shared across multiple tenants, then resource efficiency is improved, but unauthorized access and security risks increase
Solution Approach 1:
The patent implements feedback mechanisms through policy validation that continuously monitors and controls access requests between virtual agents and container instances. The system validates subnet associations and enforces policies to prevent unauthorized access while maintaining efficient resource sharing.
Solution Approach 2:
The patent changes the security parameter from static isolation to dynamic subnet-based validation. By using Resource Principal Session Tokens (RPST) to encode subnet associations and validating these parameters during policy enforcement, the system enables secure efficient resource sharing across tenancies.
3Object-affected harmful factors
If strict subnet matching policies are enforced, then security and isolation are improved, but system complexity and request validation overhead increase
Solution Approach 1:
The patent performs preliminary action by pre-associating subnets with virtual agents during resource provisioning and encoding this information in Resource Principal Session Tokens. This preliminary configuration reduces runtime complexity by avoiding dynamic subnet discovery and validation during request processing.
4Reliability
If subnet-based policy validation is implemented, then unauthorized access is prevented, but request processing time and validation overhead increase
Solution Approach 1:
The patent performs preliminary action by pre-associating subnets with virtual agents during resource provisioning and encoding this information in Resource Principal Session Tokens. This preliminary configuration reduces runtime complexity by avoiding dynamic subnet discovery and validation during request processing.
Data Source
AI summary
Techniques for a container orchestration system are disclosed. A container instance control plane receives a request corresponding to a container instance associated with a particular subnet. The container instance control plane determines if a first subnet assigned to the virtual agent matches the particular subnet associated with the container instance. Responsive to determining that the first subnet assigned to the virtual agent matches the particular subnet associated with the container instance, the container instance control plane permits the request corresponding to the container instance. Based at least on the request being permitted, the container instance control plane executes at least one operation corresponding to the request.


