Tag-Based Policy Configuration for Virtual Workloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current configuration techniques for virtual machines in data centers, such as single policy configuration and workload-based approaches, lack flexibility and scalability, making it difficult to customize networking, security, and operational settings according to specific user requirements within a single enforcement point or workflow.
Innovation Solution
A method that involves storing multiple policies for operational parameters, associating tags with these policies, and generating configuration parameters for data path components based on retrieved policies during virtual computing instance deployment, allowing for flexible and scalable configuration of networking, security, and operational settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If workload-based policy configuration is used to customize networking, security, and operational configurations for each VM and workload, then flexibility and customization are improved, but scalability deteriorates
Solution Approach 1:
The patent segments the configuration system into two independent parts: policy definitions (stored in a policy store) and policy assignments (applied to workloads via tags). This separation allows policies to be defined once and reused across multiple workloads, improving scalability while maintaining customization. The policy store contains configuration parameters that can be independently managed from their application to specific workloads.
Solution Approach 2:
The patent creates universal policy objects that can be applied to multiple different workloads through tag-based matching. A single policy definition can serve multiple purposes across different VMs and workflows by associating it with reusable tags, allowing the same configuration to be universally applied wherever the corresponding tags are present, thus improving both flexibility and scalability.
2Adaptability or versatility
If endpoint-based policy configuration is used with multiple policies for each enforcement point, then customization is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary layer (the policy store with tag-based policies) between the enforcement points and workload configurations. Instead of directly configuring each endpoint individually, the system uses intermediate policy objects that are matched to workloads through tags. This intermediary simplifies the overall system by providing a centralized policy management mechanism that reduces the complexity of direct endpoint configuration.
3Ease of operation
If single global policy configuration is used for each networking, security, and operational aspect, then ease of operation is improved, but adaptability deteriorates
Solution Approach 1:
The patent applies local quality by allowing different policy configurations to be applied to different workloads based on their specific tags, while maintaining a simple global policy structure. Each workload receives customized configuration through tag-based policy matching, but the policy definitions themselves remain standardized and centrally managed. This enables local customization without sacrificing operational simplicity.
Data Source
AI summary
A method of configuring networking, security, and operational parameters of workloads deployed in a virtualized computing environment includes the steps of: storing multiple policies, each defining one of networking, security, or operational parameters, and associating tags to each of the multiple policies, independent of deployment of a virtual computing instance in the virtual computing environment; responsive to a request to perform configuration of a virtual computing instance being deployed, retrieving policies among the stored multiple policies that are associated with same tags as tags contained in the request; generating configuration parameters for data path components in a host machine of the virtual computing instance and for data path components of the virtual computing instance based on the retrieved policies; and transmitting the generated configuration parameters to the host machine for the host machine to configure the networking, security, or operational parameters the virtual computing instance therewith.


