Dynamic Authorization for Secured Cloud Instance Bootstrap
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud service providers limit the configuration options for instances within a cluster, restricting customers' ability to run certain workloads due to predefined instance images and shapes, which do not accommodate diverse workload requirements.
Innovation Solution
Allowing customers to create custom instance shapes and images, and permitting dynamic or static group membership based on rules, enabling instances to join clusters hosted within the cloud service provider's infrastructure or on customer premises, with authentication using cluster credentials for secure workload distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud service providers use predefined instance images and shapes, then cluster management is simplified and security is improved, but customer flexibility and adaptability to diverse workload requirements deteriorate
Solution Approach 1:
The patent segments cluster configuration into modular components: instance shapes define hardware specifications (CPU, memory, storage), instance images define software configurations (operating system, runtime environment), and cluster templates combine these with workload requirements. This segmentation allows customers to mix and match components to create customized configurations without overwhelming complexity.
Solution Approach 2:
The patent implements pre-configured instance shapes and images that are prepared in advance by the cloud service provider. These pre-configured templates contain standard hardware specifications and software environments, allowing customers to quickly deploy workloads without building configurations from scratch, thus maintaining simplicity while enabling customization.
2Adaptability or versatility
If cloud service providers allow custom instance configurations, then customer adaptability to diverse workloads is improved, but system complexity and authentication management deteriorate
Solution Approach 1:
The patent implements dynamic authorization where instance permissions and cluster access rights are not fixed but can be modified based on workload requirements and security policies. Authorization rules can be updated without reconfiguring the entire system, allowing flexible instance customization while maintaining manageable security through dynamic policy adjustments.
Solution Approach 2:
The patent introduces cluster templates as an intermediary layer between custom instance configurations and authentication management. Templates encapsulate both the technical configuration (instance shapes, images) and security policies (authorization rules, credentials), separating configuration complexity from authentication complexity and allowing independent management of each aspect.
3Productivity
If predefined cluster configurations are used, then deployment speed is improved, but ability to meet specific workload demands deteriorates
Solution Approach 1:
The patent prepares instance shapes, images, and cluster templates in advance with common workload requirements pre-configured. This preliminary action allows customers to rapidly deploy instances by selecting from pre-prepared configurations, maintaining high deployment speed while the modular nature of templates enables adaptation to specific workload demands through configuration selection and modification.
Solution Approach 2:
The patent enables parameter customization within instance shapes (CPU cores, memory size, storage capacity) and images (software versions, configuration parameters). By allowing parameter changes within predefined templates, the system maintains the deployment speed of using templates while adapting to specific workload requirements through parameter adjustment.
Data Source
AI summary
In some implementations, the techniques may include receiving a request to launch a first instance in a customer partition. The request can identify one or more of a cluster and an instance image. In addition, the techniques may include launching the first instance on a server in the customer partition using the instance image identified by the request. The techniques may include receiving a request to authenticate the first instance. Moreover, the techniques may include in response to a determination that the first instance is authentic: adding the first instance to the cluster identified in the request.


