Runtime Observability Service for Secure Workspaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing observability solutions for secure workspaces are inefficient due to the need for admin-level privileges, large footprint observability tools, and inability to observe applications at runtime without rebooting.
Innovation Solution
A runtime observability service is integrated into secure workspaces, allowing selective enablement at runtime to observe applications without admin privileges and without requiring a reboot, using a small footprint observability service that gathers information and relays it to a workspace agent and then to a management service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional observability solution is deployed in a secure workspace, then observability capability is achieved, but the workspace size increases significantly and deployment becomes complex
Solution Approach 1:
The patent extracts the observability functionality from traditional bulky deployment packages and implements it as a lightweight native service within the secure workspace. This service integrates directly with the workspace runtime, eliminating the need for separate observability tool deployments and reducing overall system complexity.
Solution Approach 2:
The observability service is designed to be universal across different secure workspace types (Windows and Linux-based), providing consistent observability capabilities through a single implementation approach rather than requiring separate solutions for each workspace type.
2Productivity
If observability tools are deployed at runtime, then real-time monitoring is enabled, but system reboot is required which causes downtime
Solution Approach 1:
The observability service is pre-configured within the secure workspace image, so that when the workspace is created or restarted, the service is automatically available without requiring additional deployment steps or reboots. This preliminary preparation enables immediate runtime observability.
3Measurement precision
If admin-level privileges are granted for observability, then comprehensive monitoring is achieved, but user experience degrades and antivirus solutions block functionality
Solution Approach 1:
The workspace agent acts as an intermediary between the observability service and the host system, enabling comprehensive monitoring through the secure workspace's own service account rather than requiring admin-level privileges. This intermediary approach maintains monitoring effectiveness while avoiding the negative impacts of elevated permissions.
4Ease of manufacture
If a small footprint observability service is used, then deployment efficiency improves, but the service may lack comprehensive monitoring capabilities
Solution Approach 1:
The patent merges the observability service with the existing workspace agent infrastructure, combining lightweight service deployment with comprehensive monitoring capabilities that leverage the agent's existing communication channels and integration points with the host system.
Data Source
AI summary
Runtime observability can be enabled for applications hosted in a secure workspace. An observability service can be included in a secure workspace deployed on a user computing device and can be selectively enabled at runtime to observe one or more applications hosted in the secure workspace. The observability service can gather information about any application it observes and provide the information to a workspace agent that is also executed in the secure workspace. The workspace agent can then relay the information to a host agent that runs on the user computing device which in turn can relay the information to a management service hosted on a management server. An administrator can then use an observability solution to analyze the information.


