SD-WAN Edge Container Deployment With Resource Checks and Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manually deploying containerized workloads on SD-WAN edge devices is laborious, error-prone, and results in less effective deployment due to the numerous interdependent steps involved, which can lead to resource inefficiencies and increased operating expenses.
Innovation Solution
A computer-implemented method that automates the deployment of containerized workloads by performing pre-deployment sanity checks, setting up security constructs, and continuously monitoring resource health, while using meta-scheduling to optimize workload placement based on context elements such as tenancy, compliance, resource capacity, and proximity to clients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual deployment of containerized workloads is performed, then deployment control and customization are maintained, but labor intensity increases and error rate rises
Solution Approach 1:
The patent performs pre-deployment sanity checks to confirm resource availability before deploying containerized workloads. This preliminary action validates resource quotas, checks buffer sizes, and verifies system capacity in advance, preventing deployment failures and reducing manual intervention needs while maintaining deployment control.
Solution Approach 2:
The patent implements continuous monitoring of resource health and deployment status, sending acknowledgments back to remote managers. This feedback mechanism provides real-time information about deployment success, resource utilization, and system state, enabling automated adjustments and reducing errors through closed-loop control.
2Reliability
If security constructs are set up to isolate network functions, then security and reliability are improved, but system complexity increases
Solution Approach 1:
The patent sets up security constructs that segment and isolate SD-WAN network functions from containerized workloads using separate namespaces and security contexts. This segmentation ensures that network functions remain protected while workloads run in isolated containers, providing security without requiring complex cross-layer configurations.
Solution Approach 2:
The patent introduces containerization as an intermediary layer between SD-WAN network functions and workload applications. This intermediary provides built-in isolation through container namespaces, cgroups, and security contexts, simplifying security configuration compared to direct host-level isolation while maintaining strong security boundaries.
3Reliability
If pre-deployment sanity checks are performed, then deployment reliability is improved, but deployment time increases
Solution Approach 1:
The patent performs sanity checks on resource availability, buffer size, and system capacity before deployment to ensure successful workload placement. These checks are automated and use cached resource information to minimize overhead, preventing failed deployments and reducing the need for manual troubleshooting and re-deployment.
Solution Approach 2:
The patent performs focused sanity checks on critical resources (buffer size, memory, CPU capacity) rather than exhaustive system validation. This partial action approach checks only the most important deployment prerequisites, achieving high reliability without excessive time consumption from comprehensive system scanning.
Data Source
AI summary
Computer-implemented methods, media, and systems for automating secured deployment of containerized workloads on edge devices are disclosed. One example computer-implemented method includes receiving, by a software defined wide area network (SD-WAN) edge device and from a remote manager, resource quotas for a compute service to be enabled at the SD-WAN edge device. Pre-deployment sanity checks are performed by confirming availability of resources satisfying the resource quotas, where the resources are at the SD-WAN edge device. In response to the confirmation of the availability of resources satisfying the resource quotas, one or more security constructs are set up to isolate SD-WAN network functions at the SD-WAN edge device from the compute service at the SD-WAN edge device. The compute service is attached to a SD-WAN network by the SD-WAN edge device. An acknowledgement that the compute service is enabled at the SD-WAN edge device is sent to the remote manager.


