IP Library Granted Patent US 11,003,650
Granted Patent B2
US 11,003,650 · App. 16/111,919 · Granted May 11, 2021

Container-image reproduction and debugging

Inventor: Vincent Batts (Raleigh, NC)
Assignee: Red Hat, Inc.
G06F16/2282G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,003,650
App. No.
16/111,919
Granted
May 11, 2021
Kind
B2
Abstract

Some examples of the present disclosure relate to container-image replication. One example includes a computing device that can generate a container image. The container image can include metadata that is consumable by a container engine for deploying a container with settings specified in the metadata. The computing device can also generate provenance data indicating at least one aspect related to the generation of the container image. The computing device can modify the metadata in the container image to include an indicator of the provenance data. The computing device can then store the container image and the provenance data in one or more repositories accessible to a client device. This may enable the client device to reproduce the container image at a future point in time.

Claims (34)

1. A system comprising:

a processing device; and

a memory device that includes instructions executable by the processing device for causing the processing device to:

generate a container image that includes a metadata file, wherein the metadata file specifies settings for a container in a first format that is configured to be consumed by a container engine for deploying the container with the settings specified in the metadata file;

generate provenance data indicating at least one aspect related to the generation of the container image;

modify the metadata file in the container image to include an indicator of the provenance data in a second format that is configured to be ignored by the container engine when deploying the container; and

store the container image and the provenance data in one or more repositories accessible to a client device.

2. The system of claim 1 , wherein the metadata file is a manifest file of the container image.

3. The system of claim 1 , wherein the indicator is in a format that is unknown to the container engine, thereby causing the container engine to ignore the indicator when deploying the container.

4. The system of claim 1 , wherein the indicator is separate from the provenance data and indicates a location from which the provenance data is obtainable, the location being external to the container image.

5. The system of claim 1 , wherein the indicator includes the provenance data.

6. The system of claim 1 , wherein the provenance data includes information about another container image from which the container image was generated.

7. The system of claim 1 , wherein the provenance data includes one or more commands issued to a build tool in order to build the container image.

8. The system of claim 1 , wherein the provenance data includes one or more characteristics of a system environment in which the container image was generated.

9. The system of claim 1 , wherein the provenance data includes debugging information resulting from generating the container image.

10. The system of claim 1 , wherein the memory device further includes instructions executable by the processing device for causing the processing device to cryptographically sign the metadata file or another file that refers to the metadata file.

11. The system of claim 1 , wherein the indicator includes a Multipurpose Internet Mail Extensions (MIME) type that is not compliant with Open Container Initiative (OCI) standards.

12. A method comprising:

generating, by a processing device, a container image that includes a metadata file that is consumable by a container engine for deploying a container having settings specified in the metadata file;

generating, by the processing device, provenance data indicating at least one aspect related to the generation of the container image;

modifying, by the processing device, the metadata file in the container image to include the provenance data; and

storing, by the processing device, the container image and the provenance data in one or more repositories accessible to a client device.

13. The method of claim 12 , wherein the metadata file is a manifest file of the container image.

14. The method of claim 12 , further comprising modifying the metadata file to include an indicator that is separate from the provenance data, wherein the indicator indicates a location from which additional provenance data is obtainable, the location being external to the container image.

15. The method of claim 14 , wherein the indicator is configured to be ignored by the container engine when deploying the container.

16. A non-transitory computer-readable medium comprising program code that is executable by a processing device for causing the processing device to:

generate a container image that includes a metadata file that is consumable by a container engine for deploying a container having settings specified in the metadata file;

generate provenance data indicating at least one aspect related to the generation of the container image;

modify the metadata file in the container image to include the provenance data; and

store the container image and the provenance data in one or more repositories accessible to a client device.

17. The non-transitory computer-readable medium of claim 16 , wherein the provenance data is generated subsequently to, and independently of, the metadata file being generated.

18. The non-transitory computer-readable medium of claim 16 , further comprising program code that is executable by the processing device for causing the processing device to modify the metadata file to include an indicator that is separate from the provenance data, wherein the indicator indicates a location from which additional provenance data is obtainable, the location being external to the container image.

19. The non-transitory computer-readable medium of claim 18 , wherein the indicator is configured to be ignored by the container engine when deploying the container.

20. The non-transitory computer-readable medium of claim 16 , wherein the metadata file is a manifest file of the container image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2021
From: BATTS, VINCENT
To: RED HAT, INC.
Reel/Frame 055059/0629 →
Continuity (1)
Related Publication 20200065409A1 · Feb 27, 2020