Service Mesh Address Mapping for Private IP Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized and containerized environments, monitoring performance metrics and analytics for namespaces and service meshes is limited by the unavailability of private IP addresses, which hinders effective troubleshooting and remedial actions, as existing systems rely on public IP addresses for communication.

Innovation Solution

The introduction of a Service Mesh Address Mapping System (SMAMS) that exposes private IP addresses to monitoring systems, allowing for enhanced monitoring and analytics by providing up-to-date public-private IP mappings, enabling the use of AI/ML techniques to identify performance issues and facilitate remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private IP addresses are not exposed to monitoring systems, then network security and abstraction are maintained, but performance monitoring and troubleshooting capabilities are limited

Engineering Contradiction:
Improveperformance monitoring capabilityVSAvoidavailability of private IP addresses
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary component (service mesh gateway or monitoring agent) that sits between the private network environment and the monitoring system. This intermediary captures performance metrics and troubleshooting data from private IP addresses and forwards it to monitoring systems that may only have access to public IP addresses, thus resolving the information availability issue without compromising network security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copies of performance data and troubleshooting information from the private network environment. Monitoring agents collect metrics, logs, and performance data from services using private IP addresses and generate duplicate information streams that can be analyzed by external monitoring systems without exposing the actual private network infrastructure

Inventive Principle:
Principle #26Copying

2Ease of operation

If service mesh abstraction is implemented, then communication interface design is simplified, but detailed performance analysis and troubleshooting are hindered

Engineering Contradiction:
Improvecommunication interface designVSAvoidperformance metric analysis
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where monitoring agents continuously collect performance metrics from the service mesh and provide detailed feedback to operators and automated systems. This feedback loop enables detailed performance analysis and troubleshooting while maintaining the abstraction benefits, as the feedback provides granular information about individual service interactions through the mesh

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent segments the monitoring function into distributed monitoring agents deployed at various points within the service mesh architecture. Each agent monitors specific services or communication paths independently, allowing detailed performance analysis of individual components while preserving the overall abstraction layer. This segmentation enables granular troubleshooting without requiring changes to the communication interface design

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11606329B1Systems and methods for performance monitoring of service mesh-based environments
Publication Date: 2023.03.14 VERIZON PATENT & LICENSING INC
  • US11606329B1 patent drawing
  • US11606329B1 patent drawing
  • US11606329B1 patent drawing

AI summary

A system described herein may provide a technique for providing updated address mapping information associated with a service mesh via which one or more containerized instances communicate. The system may include and/or implement an application programming interface (“API”) via which the service mesh may provide address mapping information, that includes public and private addresses associated with containerized instances that communicate via the service mesh. The updated information may be received on an ongoing basis, and may be provided to another system that has subscribed to receiving updated mapping information associated with one or more containerized instances.