IP Library Granted Patent US 11,470,119
Granted Patent B2
US 11,470,119 · App. 15/384,129 · Granted Oct 11, 2022

Native tag-based configuration for workloads in a virtual computing environment

Inventors: Kaushal Bansal (Sunnyvale, CA); Uday Masurekar (Sunnyvale, CA)
Assignee: NICIRA, INC.
H04L63/20G06F9/45558H04L41/0806H04L41/0893G06F2009/45587G06F2009/45595H04L63/0218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,470,119
App. No.
15/384,129
Granted
Oct 11, 2022
Kind
B2
Abstract

A method of configuring networking, security, and operational parameters of workloads deployed in a virtualized computing environment includes the steps of: storing multiple policies, each defining one of networking, security, or operational parameters, and associating tags to each of the multiple policies, independent of deployment of a virtual computing instance in the virtual computing environment; responsive to a request to perform configuration of a virtual computing instance being deployed, retrieving policies among the stored multiple policies that are associated with same tags as tags contained in the request; generating configuration parameters for data path components in a host machine of the virtual computing instance and for data path components of the virtual computing instance based on the retrieved policies; and transmitting the generated configuration parameters to the host machine for the host machine to configure the networking, security, or operational parameters the virtual computing instance therewith.

Claims (27)

1. A method of configuring a virtual computing instance for execution in a virtual computing environment, comprising:

storing multiple policies, each defining one or more security or operational parameters for virtual computing instances, the security or operational parameters comprising one or more of:

load balancing configuration parameters; or

network address translation configuration parameters;

associating tags to one or more of the multiple policies such that the tags, when applied to a virtual computing instance, identify a set of the policies to apply to the virtual computing instance;

receiving a request to configure a virtual computing instance being deployed, the request including information identifying a template, the template specifying one or more first tags of the tags, wherein the request further includes a second tag not specified in the template;

responsive to the request, retrieving policies among the stored multiple policies that are associated with same tags as the one or more first tags specified in the identified template;

generating configuration parameters for data path components in a host machine of the virtual computing instance and for data path components of the virtual computing instance based on the retrieved policies, wherein if a first policy of the retrieved policies that is associated with a first tag of the one or more first tags conflicts with a second policy that is associated with the second tag, the second policy is used instead of the first policy; and

transmitting the generated configuration parameters to the host machine for the host machine to configure the security or operational parameters of the virtual computing instance therewith.

2. The method of claim 1 , wherein the host machine includes a virtualization layer that supports execution of the virtual computing instance in the host machine, the virtualization layer including a logical switch to which a virtual network interface controller of the virtual computing instance is connected for communication with other computing entities.

3. The method of claim 2 , wherein the request includes an identification of a logical port of the logical switch to which the virtual network interface controller is connected, and the configuration parameters are generated based on the retrieved policies and the identification of the logical switch.

4. The method of claim 1 , wherein one of the tags is associated with more than one policy.

5. A virtualized computing system comprising:

a host machine having a virtualization layer that supports execution of virtual computing instances;

a first management server configured to manage deployment of virtual computing instances on the host machine; and

a second management server configured to perform configuration of virtual computing instances deployed by the first management server,

wherein the second management server:

stores multiple policies, each defining one or more security or operational parameters for virtual computing instances, the security or operational parameters comprising one or more of:

load balancing configuration parameters; or

network address translation configuration parameters;

associates tags to one or more of the multiple policies such that the tags, when applied to a virtual computing instance, identify a set of the policies to apply to the virtual computing instance;

receives a request to configure a virtual computing instance being deployed on the host machine, the request including information identifying a template, the template specifying one or more first tags of the tags, wherein the request further includes a second tag not specified in the template;

responsive to the request, retrieving policies among the stored multiple policies that are associated with same tags as tags specified in the identified;

generates configuration parameters for data path components in the host machine and for data path components of the virtual computing instance based on the retrieved policies, wherein if a first policy of the retrieved policies that is associated with a first tag of the one or more first tags conflicts with a second policy that is associated with the second tag, the second policy is used instead of the first policy; and

transmits the generated configuration parameters to the host machine for the host machine to configure the security or operational parameters of the virtual computing instance therewith.

6. The system of claim 5 , wherein the virtualization layer includes a logical switch to which a virtual network interface controller of the virtual computing instance is to be connected for communication with other computing entities.

7. The system of claim 6 , wherein the request includes an identification of a logical port of the logical switch to which the virtual network interface controller is connected, and the configuration parameters are generated based on the retrieved policies and the identification of the logical switch.

Assignments (3)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2019
From: BANSAL, KAUSHAL; MASUREKAR, UDAY
To: VMWARE, INC.
Reel/Frame 049177/0673 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2019
From: BANSAL, KAUSHAL; MASUREKAR, UDAY
To: NICIRA, INC.
Reel/Frame 049177/0701 →