Unified Multi-Cluster Access with Cross-Cluster Role Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cluster management systems fail to provide effective and efficient user access to multi-cluster and multi-tenant environments, requiring manual account creation and different interfaces for each computing cluster, leading to an inefficient decentralized setup.
Innovation Solution
A centralized system is implemented where a primary computing cluster is bootstrapped to secondary clusters, allowing users to access them via a persistent connection using a single interface, with credentials and roles bound to multiple clusters, enabling seamless access and management across multiple computing environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual account creation and separate interfaces are used for each computing cluster, then user access control is maintained, but system complexity and operational difficulty increase
Solution Approach 1:
The patent merges multiple separate cluster interfaces into a single unified interface that provides access to multiple computing clusters. The system combines authentication mechanisms and user management across clusters, allowing users to access multiple clusters through one interface instead of creating separate accounts for each cluster.
Solution Approach 2:
The patent implements a universal interface that serves multiple functions: it provides authentication, authorisation, and access management across multiple computing clusters simultaneously. This single interface is designed to be multi-functional, handling various user access scenarios across different clusters without requiring separate specialized interfaces.
2Stability of the object's composition
If separate interfaces are provided for each computing cluster, then cluster independence is maintained, but user efficiency and accessibility deteriorate
Solution Approach 1:
The patent introduces an intermediary system that sits between users and multiple computing clusters. This intermediary interface manages the complexity of interacting with multiple independent clusters by providing a unified access point. The intermediary handles authentication, authorisation, and request routing, allowing users to access multiple clusters without directly managing their independence.
3Adaptability or versatility
If decentralized user management is implemented across multiple clusters, then autonomy is preserved, but time consumption and operational overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing authorisation relationships and credentials between clusters before users need to access them. The system performs advance configuration of trust relationships, authentication mechanisms, and access policies, so that when users need to access multiple clusters, the groundwork is already in place and they can proceed without time-consuming setup.
Data Source
AI summary
Disclosed herein are system, method, and computer program product embodiments for multi-cluster access. In some embodiments, the server receives a first request to bind one or more cluster roles associated with a user to each of one or more secondary computing clusters. The server binds the user's credentials with the one or more cluster roles corresponding to each of one or more secondary computing clusters. Furthermore, the server receives a second request for providing the user access to the primary computing cluster. Moreover, the server receives a third request from the user interface intended for at least one secondary computing cluster. The server forwards the third request to the at least one secondary computing cluster while impersonating at least one cluster role of the one or more cluster roles corresponding to the at least one secondary computing cluster.


