IP Library Granted Patent US 12683864
Granted Patent B2
US 12683864 · App. 18/098,071 · Granted Jul 14, 2026

Defining service policies for third-party container clusters

Inventors: Jianjun Shen (Redwood City, CA); Zhengsheng Zhou (Beijing, CN); Yves Fauser (Munich, DE); Satya Jain (Bangalore, IN); Snehal Shankar More (Pune, IN); Indresh Mishra (Pune, IN); Wenfeng Liu (Beijing, CN); Donghai Han (Beijing, CN)
Assignee: VMware LLC
H04L41/0895H04L41/0894H04L41/122
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683864
App. No.
18/098,071
Granted
Jul 14, 2026
Kind
B2
Abstract

Policies are defined for a container cluster that is configured by a first software defined network (SDN) controller cluster. A second SDN controller cluster for defining service policies that are not defined by the first SDN controller cluster receives, from a set of one or more adapters deployed in the container cluster for the second SDN controller cluster, resource identifiers for several resources of the container cluster. The second SDN controller cluster uses the resource identifiers to define a set of service policies. Then, the second SDN controller cluster distributes the set of service policies to a set of network elements to enforce the set of service policies on data messages associated with machines deployed in the container cluster configured by the first SDN controller cluster.

Claims (55)

1 . A method for defining policies for a container cluster that is configured by a first software defined network (SDN) controller cluster, the method comprising:

at a second SDN controller cluster for defining service policies that are not defined by the first SDN controller cluster:

receiving, from a set of one or more adapters deployed in a first container cluster configured by the first SDN controller cluster for the second SDN controller cluster, a first plurality of resource identifiers for a plurality of resources of the container cluster;

using the first plurality of resource identifiers to define a set of service policies for the first container cluster; and

distributing the set of service policies to a set of network elements to enforce the set of service policies on data messages associated with machines deployed in the container cluster configured by the first SDN controller cluster;

wherein the container cluster is a first container cluster, the set of adapters is a first set of adapters, the plurality of resource identifiers for a plurality of resources is a first plurality of resource identifiers for a first plurality of resources, the set of service policies is a first set of service policies, and the set of network elements is a first set of network elements, the method further comprising:

at the second SDN controller cluster:

receiving, from a second set of one or more adapters deployed in a second container cluster configured by a third SDN controller cluster for the second SDN controller cluster, a second plurality of resource identifiers for a second plurality of resources of the second container cluster that is configured by a third SDN controller cluster; and

using the second plurality of resource identifiers to define a second set of service policies for the second container clusters to enforce on data messages associated with containers in the second container cluster configured by the third SDN controller cluster;

wherein:

the first container cluster is configured by the first SDN controller cluster;

a first set of adapters is deployed in the first container cluster and is associated with the second SDN controller cluster and configured to transmit resource identifiers to the second SDN controller cluster;

a first set of network elements resides in the first container cluster; and

a second container cluster is configured by a third SDN controller cluster, with a second set of adapters deployed in the second container cluster and associated with the second SDN controller cluster and configured to transmit resource identifiers to the second SDN controller cluster; and

the receiving, using, and distributing steps are performed by the second SDN controller cluster.

2 . The method of claim 1 , wherein the container cluster is in a first datacenter and the second SDN controller cluster configures containers in a second, different datacenter.

3 . The method of claim 2 , wherein the first datacenter belongs to a first entity and the second datacenter belongs to a second, different entity.

4 . The method of claim 1 , wherein the second SDN controller cluster resides in a particular public cloud.

5 . The method of claim 4 , wherein the particular public cloud is managed by a particular public cloud provider.

6 . The method of claim 5 , wherein the second SDN controller cluster operate in a particular availability zone of the particular public cloud provider.

7 . The method of claim 6 , wherein the container cluster is a first container cluster, and the first container cluster configured by the first container cluster and a second container cluster configured by the second SDN controller cluster operate in a particular datacenter of the particular public cloud provider.

8 . The method of claim 1 , wherein the set of network elements resides in the container cluster, the method further comprising distributing the set of service policies to the set of network elements to enforce on data messages associated with the machines deployed in the container cluster configured by the first SDN controller cluster.

9 . The method of claim 8 , wherein:

the first SDN controller cluster is a Kubernetes SDN controller cluster,

the second SDN controller cluster is a network virtualization controller cluster that configures virtual machines (VMs) of a logical network, and

distributing a set of service policies to the container cluster comprises distributing the set of service policies to a third SDN controller cluster operating in the container cluster for the third SDN controller cluster to distribute the set of service policies to the set of network elements.

10 . The method of claim 9 , wherein the second SDN controller cluster also configures containers.

11 . The method of claim 1 , wherein the set of network elements resides in the container cluster, the method further comprising distributing the set of service policies to the set of network elements to enforce the set of service policies on data messages exchanged between the machines deployed in the container cluster configured by the first SDN controller cluster and machines configured by the second SDN controller cluster.

12 . The method of claim 1 , wherein the first set of network elements resides in the second container cluster, the method further comprising distributing the second set of service policies to the first set of network elements to enforce the second set of service policies on data messages exchanged between machines deployed in the second container cluster configured by the third SDN controller cluster and machines configured by the second SDN controller cluster.

13 . The method of claim 1 further comprising distributing the second set of service policies to a second set of network elements to enforce the second set of service policies.

14 . The method of claim 13 , wherein:

the first set of network elements resides in the first container cluster,

the second set of network elements resides in the second container cluster, and

the first and second sets of service policies are to be enforced by the first and second sets of network elements on data messages exchanged between machines deployed in the first container cluster configured by the first SDN controller cluster and machines deployed in the second container cluster configured by the third SDN controller cluster.

15 . A non-transitory machine readable medium storing a program for execution by at least one processing unit for defining policies for a container cluster that is configured by a first software defined network (SDN) controller cluster, the program comprising sets of instructions for:

at a second SDN controller cluster for defining service policies that are not defined by the first SDN controller cluster:

receiving, from a set of one or more adapters deployed in a first container cluster configured by the first SDN controller cluster for the second SDN controller cluster, a first plurality of resource identifiers for a plurality of resources of the container cluster;

using the plurality of resource identifiers to define a set of service policies for the first container cluster; and

distributing the set of service policies to a set of network elements to enforce the set of service policies on data messages associated with machines deployed in the container cluster configured by the first SDN controller cluster;

wherein the container cluster is a first container cluster, the set of adapters is a first set of adapters, the plurality of resource identifiers for a plurality of resources is a first plurality of resource identifiers for a first plurality of resources, the set of service policies is a first set of service policies, and the set of network elements is a first set of network elements, the method further comprising:

at the second SDN controller cluster:

receiving, from a second set of one or more adapters deployed in a second container cluster configured by a third SDN controller cluster for the second SDN controller cluster, a second plurality of resource identifiers for a second plurality of resources of the second container cluster that is configured by a third SDN controller cluster; and

using the second plurality of resource identifiers to define a second set of service policies for the second container clusters to enforce on data messages associated with containers in the second container cluster configured by the third SDN controller cluster;

wherein:

the first container cluster is configured by the first SDN controller cluster;

a first set of adapters is deployed in the first container cluster and is associated with the second SDN controller cluster and configured to transmit resource identifiers to the second SDN controller cluster;

a first set of network elements resides in the first container cluster; and

a second container cluster is configured by a third SDN controller cluster, with a second set of adapters deployed in the second container cluster and associated with the second SDN controller cluster and configured to transmit resource identifiers to the second SDN controller cluster; and

the receiving, using, and distributing steps are performed by the second SDN controller cluster.

16 . The non-transitory machine readable medium of claim 15 , wherein the set of network elements resides in the container cluster, the program comprising further instructions for distributing the set of service policies to the set of network elements to enforce on data messages associated with the machines deployed in the container cluster configured by the first SDN controller cluster.

17 . The non-transitory machine readable medium of claim 16 , wherein

the first SDN controller cluster is a Kubernetes SDN controller cluster,

the second SDN controller cluster is a network virtualization controller cluster that configures virtual machines (VMs) of a logical network, and

the set of instructions for distributing the set of service policies to the container cluster comprises a set of instructions for distributing the set of service policies to a third SDN controller cluster operating in the container cluster for the third SDN controller cluster to distribute the set of service policies to the set of network elements.

18 . The non-transitory machine readable medium of claim 17 wherein the second SDN controller cluster also configures containers.