Declarative Policy Management for Cloud Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software-defined data centers face challenges in automating policy management across multiple cloud services due to heterogeneity in resources and infrastructure silos, making it difficult to enforce policies proactively and reactively, especially when real-world policies are written in high-level terms and span multiple infrastructure components.
Innovation Solution
A system that uses a declarative policy language to integrate with cloud service management data, converting data from various sources into a unified format, and enforces policies proactively, reactively, and interactively through a user interface, allowing administrators to select corrective actions, with a compiler converting policies into database operations to manage policy violations across compute, networking, and storage resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a unified policy management system is implemented across multiple cloud services, then policy enforcement capability is improved, but system complexity increases due to heterogeneity of resources and infrastructure silos
Solution Approach 1:
The patent introduces a policy management system as an intermediary layer between cloud service providers and cloud consumers. This mediator translates high-level policy requirements into service-specific enforcement actions, handling the heterogeneity of different cloud services (compute, storage, networking) without requiring direct integration with each service's underlying infrastructure, thus improving policy enforcement while managing system complexity.
Solution Approach 2:
The policy management system is segmented into distinct functional modules: policy definition interface, policy translation engine, policy enforcement interface, and monitoring components. Each module handles specific aspects of policy management independently, allowing the system to manage complexity through modular design while maintaining comprehensive policy enforcement across multiple cloud services.
2Ease of operation
If policies are written in high-level terms (users, applications, data), then ease of policy definition is improved, but difficulty in mapping to actual cloud resources (compute, networking, storage) increases
Solution Approach 1:
The policy translation engine acts as an intermediary that automatically maps high-level policy terms (users, applications, data) to underlying cloud resource identifiers (compute instances, storage volumes, network configurations). This translation layer shields policy writers from complexity while ensuring accurate resource mapping through automated resolution of abstract terms to concrete resource references.
Solution Approach 2:
The patent creates a universal policy language that can express policies in terms of abstract concepts (users, applications, data) while simultaneously supporting mapping to diverse cloud resource types (compute, storage, networking). This multi-functional policy language allows the same high-level policy syntax to work across different cloud service domains without requiring service-specific policy definitions.
3Reliability
If proactive policy enforcement is implemented to prevent violations, then compliance level is improved, but automation complexity increases
Solution Approach 1:
The policy enforcement interface proactively evaluates proposed cloud resource actions before they are executed. By performing preliminary policy checks on intended actions (such as resource provisioning or configuration changes), the system prevents policy violations before they occur, improving compliance while automating the evaluation process through rule-based enforcement logic that reduces manual intervention complexity.
4Ease of manufacture
If piecemeal solutions focused on individual cloud services (compute, networking, storage) are used, then ease of implementation is improved, but ability to enforce policies spanning multiple infrastructure silos deteriorates
Solution Approach 1:
The patent implements a universal policy enforcement framework that can handle policies spanning multiple cloud service types (compute, storage, networking) through a single integrated system. The framework maintains service-specific enforcement capabilities while providing cross-service policy coordination, allowing organizations to implement comprehensive multi-service policies without requiring separate piecemeal solutions for each infrastructure silo.
Data Source
AI summary
Methods, apparatus, systems and articles of manufacture are disclosed related to policy declarations for cloud management system. An example computer readable storage device includes instructions that, when executed, cause processor circuitry to at least identify a proposed change to a state of a network. The example instructions, when executed, also cause the processor circuitry to, in response to identifying the proposed change, determine whether the proposed change will cause the state of the network to violate a policy, the policy including a query plan describing characteristics to evaluate the proposed change. In some examples, the instructions, when executed, cause the processor circuitry to, when the proposed change will cause the state of the network to violate the policy, execute an application programming interface call to a cloud service provider to cause the cloud service provider to prevent violation of the policy by executing an action associated with the proposed change.


