IP Library Granted Patent US 10,411,975
Granted Patent B2
US 10,411,975 · App. 13/843,512 · Granted Sep 10, 2019

System and method for a cloud computing abstraction with multi-tier deployment policy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,411,975
App. No.
13/843,512
Granted
Sep 10, 2019
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for a virtualization environment adapted for development and deployment of at least one software workload, the virtualization environment having a metamodel framework that allows the association of a policy to the software workload upon development of the workload that is applied upon deployment of the software workload.

Claims (42)

1. A method of deploying at least one workload agnostically of at least a specific cloud provider and a target environment, comprising:

providing at least one design container for development and deployment of the at least one workload, wherein the at least one design container is included in one or more logical constructs of a blueprint in a design environment, and wherein the design environment is different from the target environment;

receiving at least one resource affinity specifying deployment resources for at least one of the at least one workload, wherein the at least one resource affinity is included in the one or more logical constructs of the blueprint, wherein at least some of the one or more logical constructs of the blueprint are mapped to at least some of the deployment resources, and wherein the at least one resource affinity specifies whether all workloads within the at least one design container are to be deployed on a same resource;

receiving a deployment policy for execution of the deployment of the developed at least one workload in accordance with the received at least one resource affinity and agnostically of at least the specific cloud provider and the target environment;

deploying the at least one workload to at least one deployment resource, wherein the at least one workload is associated with at least one security zone;

determining one or more policies associated with the at least one security zone; and

enforcing the one or more policies associated with the at least one security zone while the at least one workload is deployed, wherein the enforcing further comprises:

propagating firewall rules that permit the at least one workload to be performed to multiple firewalls within and outside of the at least one security zone.

2. The method of claim 1 , wherein the specifying deployment resources comprises specifying a required deployment resource.

3. The method of claim 2 , wherein the required deployment resource comprises one of a host, a cluster, a provider, and a network.

4. The method of claim 1 , wherein the specifying deployment resources comprises specifying a forbidden deployment resource.

5. The method of claim 1 , wherein the at least one workload comprises a specification of components to be installed on, and minimum resource requirements of, a virtual machine, and wherein the at least one workload comprises a decoupling from a specific cloud provider.

6. The method of claim 1 , wherein the at least one workload defines at least one of packaging, configuration management policies, SLA, and scaling policies in a stateless fashion.

7. The method of claim 1 , further comprising receiving at least one package.

8. The method of claim 7 , wherein the at least one package comprises a bundle of scripts and binaries that automate installation of an application.

9. The method of claim 1 , further comprising providing at least one network service.

10. The method of claim 9 , wherein the at least one network service comprises a logical representation of application requirements in a runtime environment.

11. The method of claim 9 , wherein the at least one network service comprises at least one of load balancers, firewalls, and database as a service.

12. The method of claim 1 , further comprising reporting on a deployment in accordance with the deployment policy.

13. The method of claim 12 , wherein said reporting comprises an aggregated reporting across multiple tiers and multiple clouds of the deployment.

14. The method of claim 1 , wherein the deploying comprises mapping the deployment policy to available resources within a hybrid cloud environment.

15. The method of claim 1 , wherein the deployment policy comprises at least design time constraints, container resource affinity, workload resource requirements, application components, availability of required data, operating system, and required SLA.

16. The method of claim 1 , further comprising implementing a data residency policy to interoperate with the deployment policy.

17. A system comprising:

at least one processor; and

a memory storing instructions that, when executed by the at least one processor, cause the system to perform:

providing at least one design container for development and deployment of the at least one workload, wherein the at least one design container is included in one or more logical constructs of a blueprint in a design environment, and wherein the design environment is different from the target environment;

receiving at least one resource affinity specifying deployment resources for at least one of the at least one workload, wherein the at least one resource affinity is included in the one or more logical constructs of the blueprint, wherein at least some of the one or more logical constructs of the blueprint are mapped to at least some of the deployment resources, and wherein the at least one resource affinity specifies whether all workloads within the at least one design container are to be deployed on a same resource;

receiving a deployment policy for execution of the deployment of the developed at least one workload in accordance with the received at least one resource affinity and agnostically of at least the specific cloud provider and the target environment;

deploying the at least one workload to at least one deployment resource, wherein the at least one workload is associated with at least one security zone;

determining one or more policies associated with the at least one security zone; and

enforcing the one or more policies associated with the at least one security zone while the at least one workload is deployed, wherein the enforcing further comprises:

propagating firewall rules that permit the at least one workload to be performed to multiple firewalls within and outside of the at least one security zone.

18. A non-transitory computer-readable storage medium including instructions that, when executed by at least one processor of a computing system, cause the computing system to perform;

providing at least one design container for development and deployment of the at least one workload, wherein the at least one design container is included in one or more logical constructs of a blueprint in a design environment, and wherein the design environment is different from the target environment;

receiving at least one resource affinity specifying deployment resources for at least one of the at least one workload, wherein the at least one resource affinity is included in the one or more logical constructs of the blueprint, wherein at least some of the one or more logical constructs of the blueprint are mapped to at least some of the deployment resources, and wherein the at least one resource affinity specifies whether all workloads within the at least one design container are to be deployed on a same resource;

receiving a deployment policy for execution of the deployment of the developed at least one workload in accordance with the received at least one resource affinity and agnostically of at least the specific cloud provider and the target environment;

deploying the at least one workload to at least one deployment resource, wherein the at least one workload is associated with at least one security zone;

determining one or more policies associated with the at least one security zone; and

enforcing the one or more policies associated with the at least one security zone while the at least one workload is deployed, wherein the enforcing further comprises:

propagating firewall rules that permit the at least one workload to be performed to multiple firewalls within and outside of the at least one security zone.

19. The method of claim 1 , wherein deployment resources that satisfy the first set of requirements for a critical operation have one or more of a threshold low latency, threshold bandwidth capability, or guaranteed quality of service.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2026
From: VIDEOLABS, INC.
To: VL COLLECTIVE IP LLC
Reel/Frame 073579/0102 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: DXC US AGILITY PLATFORM, LLC
To: VIDEOLABS, INC.
Reel/Frame 067007/0613 →
CHANGE OF NAME Recorded Mar 14, 2024
From: CSC AGILITY PLATFORM, INC.
To: DXC US AGILITY PLATFORM, INC.
Reel/Frame 066797/0406 →
CHANGE OF NAME Recorded Mar 12, 2024
From: DXC US AGILITY PLATFORM, INC.
To: DXC US AGILITY PLATFORM, LLC
Reel/Frame 066796/0864 →
CHANGE OF NAME Recorded Dec 18, 2019
From: SERVICEMESH, INC.
To: CSC AGILITY PLATFORM, INC.
Reel/Frame 051367/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2019
From: MARTINEZ, FRANK R.; PULIER, ERIC
To: SERVICEMESH, INC.
Reel/Frame 048939/0468 →
CHANGE OF NAME Recorded Apr 4, 2019
From: SERVICEMESH, INC.
To: CSC AGILITY PLATFORM, INC.
Reel/Frame 048806/0585 →
RELEASE OF SECURITY INTEREST Recorded Jan 29, 2014
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: SERVICEMESH, INC.
Reel/Frame 032081/0252 →
Cited By (12)
US 12,250,263 US 12,294,621 US 12,340,257 US 12,388,841 US 12,388,854 US 12,511,175 US 12,547,440 US 12,632,557 US 12,634,213 US 12,695,668 US 12,699,639 US 12,712,727