Cross-tenancy resource association for container orchestration system
Techniques for a container orchestration system are disclosed. A container instance control plane receives a request corresponding to a container instance associated with a particular subnet. The container instance control plane determines if a first subnet assigned to the virtual agent matches the particular subnet associated with the container instance. Responsive to determining that the first subnet assigned to the virtual agent matches the particular subnet associated with the container instance, the container instance control plane permits the request corresponding to the container instance. Based at least on the request being permitted, the container instance control plane executes at least one operation corresponding to the request.
1 . One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:
receiving, from a virtual agent in a cloud network at a container instance control plane, a request corresponding to a container instance associated with a first subnet, wherein the virtual agent comprises a process executed external to the container instance;
determining that the virtual agent is assigned to a second subnet, wherein the second subnet is based on an identity principal corresponding to the virtual agent;
determining if the second subnet assigned to the virtual agent matches the first subnet associated with the container instance;
responsive at least to determining that the second subnet assigned to the virtual agent matches the first subnet associated with the container instance, permitting the request corresponding to the container instance; and
based at least on the request being permitted, executing at least one operation corresponding to the request.
2 . The non-transitory media of claim 1 , wherein the operations further comprise determining the second subnet, assigned to the virtual agent, based on a Resource Principal Session Token (RPST) for a session during which the request is received from the virtual agent.
3 . The non-transitory media of claim 2 , wherein the operations further comprise:
generating the RPST with an identification of the second subnet being comprised within the RPST.
4 . The non-transitory media of claim 3 , wherein determining if the second subnet assigned to the virtual agent matches the first subnet associated with the container instance comprises executing a policy that references the RPST.
5 . The non-transitory media of claim 1 , wherein the operations further comprise receiving the identity principal, corresponding to the virtual agent, concurrently with receiving the request or prior to receiving the request.
6 . The non-transitory media of claim 1 , wherein the request is permitted based further on determining that the request is received from an entity of a virtual agent type.
7 . The non-transitory media of claim 1 , wherein the request comprises a Create, Read, Update, or Delete (CRUD) request corresponding to the container instance.
8 . The non-transitory media of claim 1 , wherein the virtual agent is comprised in a virtual node and wherein the container instance is in a service tenancy and executes containers corresponding to the virtual node.
9 . The non-transitory media of claim 1 , wherein a management plane assigns the second subnet to the virtual agent.
10 . The non-transitory media of claim 1 , wherein executing the at least one operation corresponding to the request is based further on endorsement of the request, permitted by a cloud network provider of the cloud network, by a customer of the cloud network provider.
11 . The non-transitory media of claim 1 , wherein the operations further comprise:
receiving, from a second virtual agent in the cloud network at the container instance control plane, a second request corresponding to a second container instance associated with a third subnet;
determining if a fourth subnet assigned to the second virtual agent matches the third subnet associated with the second container instance; and
responsive at least to determining that the fourth subnet assigned to the second virtual agent does not match the third subnet associated with the container instance, denying the request corresponding to the container instance.
12 . The non-transitory media of claim 1 , wherein determining if the second subnet assigned to the virtual agent matches the first subnet comprises extracting subnet information from authentication credentials associated with the virtual agent.
13 . A system comprising:
at least one device including a hardware processor; and
the system being configured to perform operations comprising:
receiving, from a virtual agent in a cloud network at a container instance control plane, a request corresponding to a container instance associated with a first subnet, wherein the virtual agent comprises a process executed external to the container instance;
determining that the virtual agent is assigned to a second subnet, wherein the second subnet is based on an identity principal corresponding to the virtual agent;
determining if the second subnet assigned to the virtual agent matches the first subnet associated with the container instance;
responsive at least to determining that the second subnet assigned to the virtual agent matches the first subnet associated with the container instance, permitting the request corresponding to the container instance; and
based at least on the request being permitted, executing at least one operation corresponding to the request.
14 . The system of claim 13 , wherein the operations further comprise determining the second subnet, assigned to the virtual agent, based on a Resource Principal Session Token (RPST) for a session during which the request is received from the virtual agent.
15 . A method comprising:
receiving, from a virtual agent in a cloud network at a container instance control plane, a request corresponding to a container instance associated with a first subnet, wherein the virtual agent comprises a process executed external to the container instance;
determining that the virtual agent is assigned to a second subnet, wherein the second subnet is based on an identity principal corresponding to the virtual agent;
determining if the second subnet assigned to the virtual agent matches the first subnet associated with the container instance;
responsive at least to determining that the second subnet assigned to the virtual agent matches the first subnet associated with the container instance, permitting the request corresponding to the container instance; and
based at least on the request being permitted, executing at least one operation corresponding to the request;
wherein the method is performed by at least one device including a hardware processor.
16 . The method of claim 15 , wherein the operations further comprise determining the second subnet, assigned to the virtual agent, based on a Resource Principal Session Token (RPST) for a session during which the request is received from the virtual agent.
17 . The method of claim 16 , wherein the operations further comprise:
generating the RPST with an identification of the second subnet being comprised within the RPST.
18 . The method of claim 17 , wherein determining if the second subnet assigned to the virtual agent matches the first subnet associated with the container instance comprises executing a policy that references the RPST.
19 . The method of claim 15 , wherein the operations further comprise receiving the identity principal, corresponding to the virtual agent, concurrently with receiving the request or prior to receiving the request.
20 . The method of claim 15 , wherein determining if the second subnet assigned to the virtual agent matches the first subnet comprises extracting subnet information from authentication credentials associated with the virtual agent.