Managed Server Patch Agent Using Object Store Mailbox
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud patch management relies on human operators for maintenance windows, which is slow, error-prone, and lacks scalability as the number of managed systems grows, and often requires direct connectivity that compromises security and efficiency.
Innovation Solution
A 'pull' approach using a customer-accessible object store for secure communication via HTTPS or FTPS endpoints, where the customer initiates the patch process, and a patch agent automates the update process within agreed maintenance windows, ensuring security and traceability through shared secrets and automated bootstrap procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If human operators manually manage patches during maintenance windows, then security control is maintained, but the process becomes slow and error-prone
Solution Approach 1:
The patch management system enables automated self-service through the interaction between the patch agent on managed systems and the patch management server. The patch agent automatically discovers patches, checks applicability, and applies updates without requiring manual human intervention, while still operating within authorized maintenance windows. This automation resolves the contradiction by maintaining security through pre-negotiated maintenance windows while dramatically improving patch application speed and reducing errors.
Solution Approach 2:
The patch management server acts as an intermediary between the service provider and the managed systems. It receives patch requests from the service provider, validates them against maintenance window constraints, and coordinates with patch agents on managed systems to apply patches automatically. This intermediary role enables automated high-speed patching while maintaining the security controls established by pre-negotiated maintenance windows.
2Adaptability or versatility
If the number of managed systems grows, then service coverage expands, but manual patch management becomes less scalable
Solution Approach 1:
Each managed system runs a patch agent that autonomously discovers applicable patches, checks maintenance window constraints, and applies updates without requiring proportional increases in human operators. The patch management server automatically coordinates with multiple patch agents across numerous systems, enabling the service to scale to thousands of managed systems without increasing management complexity proportionally.
Solution Approach 2:
The patch management server provides universal functionality that serves multiple managed systems simultaneously. It handles patch discovery, applicability checking, scheduling within maintenance windows, and coordination for numerous systems through a single centralized platform. This multi-functional approach allows service coverage to expand without proportionally increasing management complexity.
3Productivity
If service provider directly connects to managed systems for updates, then patch deployment is efficient, but security concerns increase
Solution Approach 1:
The patch management server serves as a secure intermediary between the service provider and managed systems. Instead of direct connections that pose security risks, the server receives authenticated patch requests from the service provider, validates them against maintenance window constraints, and then communicates with authorized patch agents on managed systems. This intermediary architecture maintains deployment efficiency while significantly reducing security risks through centralized authentication and authorization.
Solution Approach 2:
The patch agent on each managed system autonomously authenticates with the patch management server and receives authorized patch instructions. This self-service mechanism eliminates the need for direct service provider connections to managed systems, reducing security exposure while maintaining efficient patch deployment through automated authentication and execution.
4Productivity
If automated patching is implemented, then scalability improves, but direct connectivity requirements may compromise security
Solution Approach 1:
The patch management server acts as a secure intermediary that enables automated patching without requiring direct connectivity between service provider and managed systems. It receives authenticated requests from the service provider, validates maintenance window constraints, and coordinates with patch agents on managed systems through controlled communication channels. This architecture achieves full automation and scalability while maintaining security through centralized authorization.
Solution Approach 2:
The patch agent on each managed system performs automated self-service by autonomously discovering patches, checking applicability, and applying updates based on instructions from the patch management server. This automation achieves full scalability without direct service provider connections, as the patch agent operates independently within authorized maintenance windows under the coordination of the intermediary server.
Data Source
AI summary
A method for updating software in one or more servers in a managed system includes bootstrapping of shared secrets to secure communication, using an object store with publicly accessible URLs as a mailbox system between a patch agent locally at the managed system and a patch management server located remotely. The object store provides for indirect and asynchronous communication, allowing the patch management server to manage the updates, whereas the patch agent executes the updates. The patch management server keeps track of update results, and when an update is unsuccessful it performs and supports a remediation process. Both the patch agent and the patch management server keep full logs of the update results to allow for auditing.


