IP Library Granted Patent US 12694116
Granted Patent B2
US 12694116 · App. 18/943,019 · Granted Jul 28, 2026

Managing different versions of security information in an orchestration platform

Inventors: Xinpeng Liu (Austin, TX); Jing Jing Wei (Beijing, CN); Jia Lin Wang (Beijing, CN); Ping Mei (Beijing, CN); Da Guang Sun (Changping, CN); Yang Kang (Beijing, CN); Bing Ding (Beijing, CN); Yi Fan Wu (Beijing, CN)
Assignee: International Business Machines Corporation
G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694116
App. No.
18/943,019
Granted
Jul 28, 2026
Kind
B2
Abstract

A computer-implemented method for managing versions of security information. A processor set receives a request to add a first version of security information for a number of pods in an orchestration platform. The number of pods comprises pods to be deployed in the orchestration platform. The processor set stores the first version of the security information into a set of security information in a metadata database in the orchestration platform. The set of security information comprises the security information of different versions. The processor set stores a new destination rule for the first version of the security information into a set of destination rules in the metadata database. Destination rules in the set of destination rules defines versions of the security information to be consumed by different pods from the number of pods. The processor set deploys a pod from the number of pods.

Claims (59)

1 . A computer implemented method for managing versions of security information, the computer implemented method comprising:

receiving, by a processor set, a request to add a first version of security information for a number of pods in an orchestration platform, wherein the number of pods comprises pods to be deployed in the orchestration platform;

storing, by the processor set, the first version of the security information into a set of security information in a metadata database in the orchestration platform, wherein the set of security information comprises the security information of different versions;

storing, by the processor set, a new destination rule for the first version of the security information into a set of destination rules in the metadata database, wherein destination rules in the set of destination rules defines versions of the security information to be consumed by different pods from the number of pods; and

deploying, by the processor set, a pod from the number of pods, wherein the pod from the number of pods consumes a version of the security information during deployment based on the set of destination rules.

2 . The computer implemented method of claim 1 , further comprising:

receiving, by the processor set, a second request to invalidate a second version of security information from the set of security information stored in the metadata database in the orchestration platform;

identifying, by the processor set, a subset of destination rules associated with the second version of security information from the set of destination rules stored in the metadata database in the orchestration platform; and

invalidating, by the processor set, the second version of security information from the set of security information and the subset of destination rules from the set of destination rules in the metadata database.

3 . The computer implemented method of claim 1 , wherein the deploying, by the processor set, a pod from the number of pods comprises:

extracting, by the processor set, the set of destination rules from the metadata database in the orchestration platform;

identifying, by the processor set, the version of security information for the pod from the number of pods based on the set of destination rules; and

receiving, by the processor set, the version of security information from the set of security information stored in the metadata database in the orchestration platform.

4 . The computer implemented method of claim 3 , further comprising:

converting, by the processor set, the version of security information for the pod to environment variables to be consumed by the pod.

5 . The computer implemented method of claim 3 , wherein pod labels for the pod to be deployed are extracted with the set of destination rules.

6 . The computer implemented method of claim 1 , wherein the set of destination rules are defined to map the set of security information to pod labels for pods in the number of pods.

7 . The computer implemented method of claim 1 , wherein the first version of security information is converted into a format supported by the orchestration platform.

8 . A computer system for managing versions of security information, comprising:

a processor set;

a set of one or more computer-readable storage media; and

program instructions stored on the set of one or more computer-readable storage media to cause the processor set to perform operations comprising:

receiving a request to add a first version of security information for a number of pods in an orchestration platform, wherein the number of pods comprises pods to be deployed in the orchestration platform;

storing the first version of the security information into a set of security information in a metadata database in the orchestration platform, wherein the set of security information comprises the security information of different versions;

storing a new destination rule for the first version of the security information into a set of destination rules in the metadata database, wherein destination rules in the set of destination rules defines versions of the security information to be consumed by different pods from the number of pods; and

deploying a pod from the number of pods, wherein the pod from the number of pods consumes a version of the security information during deployment based on the set of destination rules.

9 . The computer system of claim 8 , wherein the operations further comprise:

receiving a second request to invalidate a second version of security information from the set of security information stored in the metadata database in the orchestration platform;

identifying a subset of destination rules associated with the second version of security information from the set of destination rules stored in the metadata database in the orchestration platform; and

invalidating the second version of security information from the set of security information and the subset of destination rules from the set of destination rules in the metadata database.

10 . The computer system of claim 8 , wherein the deploying a pod from the number of pods comprises:

extracting the set of destination rules from the metadata database in the orchestration platform;

identifying the version of security information for the pod from the number of pods based on the set of destination rules; and

receiving the version of security information from the set of security information stored in the metadata database in the orchestration platform.

11 . The computer system of claim 10 , wherein the operations further comprise:

converting the version of security information for the pod to environment variables to be consumed by the pod.

12 . The computer system of claim 10 , wherein pod labels for the pod to be deployed are extracted with the set of destination rules.

13 . The computer system of claim 8 , wherein the set of destination rules are defined to map the set of security information to pod labels for pods in the number of pods.

14 . The computer system of claim 8 , wherein the first version of security information is converted into a format supported by the orchestration platform.

15 . A computer program product for managing versions of security information, comprising:

a set of one or more computer-readable storage media;

program instructions stored in the set of one or more computer-readable storage media to perform operations comprising:

receiving, by a processor set, a number of data pairs, wherein each data pair in the number of data pairs comprises an input data and an output data that is semantically equivalent to the input data, wherein the number of pods comprises pods to be deployed in the orchestration platform;

receiving, by a processor set, a request to add a first version of security information for a number of pods in an orchestration platform;

storing, by the processor set, the first version of the security information into a set of security information in a metadata database in the orchestration platform, wherein the set of security information comprises the security information of different versions;

storing, by the processor set, a new destination rule for the first version of the security information into a set of destination rules in the metadata database, wherein destination rules in the set of destination rules defines versions of the security information to be consumed by different pods from the number of pods; and

deploying, by the processor set, a pod from the number of pods, wherein the pod from the number of pods consumes a version of the security information during deployment based on the set of destination rules.

16 . The computer program product of claim 15 , wherein the operations further comprise:

receiving, by the processor set, a second request to invalidate a second version of security information from the set of security information stored in the metadata database in the orchestration platform;

identifying, by the processor set, a subset of destination rules associated with the second version of security information from the set of destination rules stored in the metadata database in the orchestration platform; and

invalidating, by the processor set, the second version of security information from the set of security information and the subset of destination rules from the set of destination rules in the metadata database.

17 . The computer program product of claim 15 , wherein the deploying, by the processor set, a pod from the number of pods:

extracting, by the processor set, the set of destination rules from the metadata database in the orchestration platform;

identifying, by the processor set, the version of security information for the pod from the number of pods based on the set of destination rules; and

receiving, by the processor set, the version of security information from the set of security information stored in the metadata database in the orchestration platform.

18 . The computer program product of claim 17 , wherein the operations further comprise:

converting, by the processor set, the version of security information for the pod to environment variables to be consumed by the pod.

19 . The computer program product of claim 17 , wherein pod labels for the pod to be deployed are extracted with the set of destination rules.

20 . The computer program product of claim 15 , wherein the set of destination rules are defined to map the set of security information to pod labels for pods in the number of pods.