Cloud-Native SDN Policy Generation for Continuous Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software-defined networking (SDN) architectures face challenges in cloud-native adoption due to complexity in life cycle management, scale limitations in configuration modules, and the lack of a command-line interface (CLI)-based interface, making them inefficient for modern cloud-native environments such as 5G mobile networks and enterprise use cases.
Innovation Solution
A cloud-native SDN architecture is introduced, which includes a container-based microservices architecture that supports in-service upgrades, assumes a base container orchestration platform, and integrates with cloud-native monitoring tools, leveraging Kubernetes constructs for scalable and agile network management, and automates network resource provisioning to create highly scalable virtual networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional SDN architecture is used, then network control is centralized and manageable, but life cycle management becomes complex and scalability is limited
Solution Approach 1:
The patent segments the SDN controller into multiple independent microservices that can be deployed, managed, and scaled separately. Each microservice handles specific network control functions, allowing independent lifecycle management and reducing overall system complexity while improving cloud-native adaptability
Solution Approach 2:
The patent creates a universal container orchestration layer that can manage diverse network workloads and applications across different environments. This multi-functional platform provides standardized interfaces and automation capabilities that work across various cloud-native scenarios, reducing management complexity while enhancing versatility
2Productivity
If manual network configuration is used, then network policies can be carefully controlled, but deployment efficiency is low and automation is lacking
Solution Approach 1:
The patent implements self-service automation where the system automatically generates, validates, and deploys network policies based on application definitions. The orchestration platform autonomously manages network resource provisioning and policy enforcement without manual intervention, significantly improving deployment efficiency while maintaining proper control through automated validation rules
3Loss of time
If network policies are manually created and applied, then policy accuracy can be ensured, but time consumption increases and continuous deployment is hindered
Solution Approach 1:
The patent performs preliminary validation and generation of network policies during the application definition phase. Policies are pre-configured, validated for correctness, and stored in a catalog before deployment, ensuring accuracy is maintained while enabling rapid deployment during continuous integration/continuous deployment (CI/CD) workflows
Solution Approach 2:
The patent implements automated feedback mechanisms that validate network policies during deployment and provide real-time feedback on policy correctness. The system monitors policy application status and automatically corrects or alerts on issues, maintaining policy accuracy while minimizing deployment time through iterative validation
Data Source
AI summary
In an example, a method comprises obtaining, by a policy controller from a first SDN architecture system, flow metadata for packet flows exchanged among workloads of a distributed application deployed to the first SDN architecture system; identifying, using flow metadata for a packet flow of the packet flows, a source endpoint workload and a destination endpoint workload of the packet flow; generating a network policy rule to allow packet flows from the source endpoint workload to the destination endpoint workload of the packet flow; and adding the network policy rule to a configuration repository as configuration data for a second SDN architecture system to cause a deployment system to configure the second SDN architecture system with the network policy rule to allow packet flows from the source endpoint workload to the destination endpoint workload when the distributed application is deployed to the second SDN architecture system.


