IP Library Granted Patent US 11,150,895
Granted Patent B1
US 11,150,895 · App. 16/523,785 · Granted Oct 19, 2021

Automatically deploying artifacts

Inventor: Jonathan Wall (San Francisco, CA)
Assignee: STRIPE, INC.
G06F8/71G06F8/433G06F8/65
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,150,895
App. No.
16/523,785
Granted
Oct 19, 2021
Kind
B1
Abstract

A method and apparatus for automatically deploying artifacts are disclosed. In one embodiment, the method comprises generating a trusted configuration artifact with a forward immutable continuous integration (CI) implemented as a build pipeline; accessing, by an orchestration system, the trusted configuration artifact from the IAC repository; and automatically deploying the configuration to change a state of the cluster, according to an orchestration type associated with the trusted configuration artifact, including determining the orchestration type.

Claims (34)

1. A method for orchestrating Infrastructure as Code (IAC), the method comprising:

generating a trusted configuration artifact with a forward immutable continuous integration (CI) implemented as a build pipeline having a plurality of stages with forward immutability between consecutive pipeline stages, with all assets generated in a prior stage of the plurality of stages being immutable to actors in a subsequent stage of the pipeline, wherein each subsequent stage after a first stage of the build pipeline depends on an immutable output of a previous stage in the build pipeline;

detecting, by an orchestration system, the trusted configuration artifact has been committed to an infrastructure as code (IAC) repository from a secure pipeline, the trusted configuration artifact including a description of a configuration of a cluster of one or more machines;

accessing, by the orchestration system, the trusted configuration artifact from the IAC repository; and

automatically deploying the configuration using an orchestrator of the orchestration system to change a state of the cluster, according to an orchestration type associated with the trusted configuration artifact, including determining the orchestration type associated with the orchestrator based on a configuration option associated with the trusted configuration artifact and determining the orchestrator responsible for deploying the determined orchestration type for the configuration associated with the trusted configuration artifact.

2. The method defined in claim 1 wherein automatically deploying the configuration to change the state of the cluster comprises compiling code, by the orchestration system, and signaling to one or more orchestrators to perform the update to the configuration.

3. The method defined in claim 1 wherein signaling to the one or more orchestrators comprises performing protected writes to the one or more orchestrators to interact with the cluster to update the configuration.

4. The method defined in claim 1 wherein the trusted configuration artifact is pushed to the orchestration system.

5. The method defined in claim 1 wherein the trusted configuration artifact has a provable, auditable chain of trust.

6. The method defined in claim 5 wherein the build pipeline includes an emission stage for outputting signed, trusted configuration artifact from the build pipeline.

7. The method defined in claim 5 wherein the trusted configuration artifact has been signed by a person proposing the change to the configuration and a separate peer review and approval to become committed into the IAC repository.

8. The method defined in claim 1 further comprising writing all actions taken with respect to the configuration to an append only log.

9. A non-transitory computer readable storage media having instructions stored thereupon which, when executed by a system having at least a processor and a memory therein,

cause the system to perform a method for orchestrating Infrastructure as Code (IAC), the method comprising:

generating a trusted configuration artifact with a forward immutable continuous integration (CI) implemented as a build pipeline having a plurality of stages with forward immutability between consecutive pipeline stages, with all assets generated in a prior stage of the plurality of stages being immutable to actors in the one a subsequent stage of the pipeline, wherein each subsequent stage after a first stage of the build pipeline depends on an immutable output of a previous stage in the build pipeline;

detecting the trusted configuration artifact has been committed to an infrastructure as code (IAC) repository from a secure pipeline, the trusted configuration artifact including a description of a configuration of a cluster of one or more machines;

accessing, by an orchestration system, the trusted configuration artifact from the IAC repository; and

automatically deploying the configuration using an orchestrator of the orchestration system to change a state of the cluster, according to an orchestration type associated with the trusted configuration artifact, including determining the orchestration type associated with the orchestrator based on a configuration option associated with the trusted configuration artifact and determining the orchestrator responsible for deploying the determined orchestration type for the configuration associated with the trusted configuration artifact.

10. The computer readable storage media defined in claim 9 wherein automatically deploying the configuration to change the state of the cluster comprises compiling code, by the orchestration system, and signaling to one or more orchestrators to perform the update to the configuration.

11. The computer readable storage media defined in claim 9 wherein signaling to the one or more orchestrators comprises performing protected writes to the one or more orchestrators to interact with the cluster to update the configuration.

12. The computer readable storage media defined in claim 9 wherein the trusted configuration artifact is pushed to the orchestration system.

13. The computer readable storage media defined in claim 9 wherein the trusted configuration artifact has a provable, auditable chain of trust.

14. The computer readable storage media defined in claim 13 wherein the build pipeline includes an emission stage for outputting signed, trusted configuration artifact from the build pipeline.

15. The computer readable storage media defined in claim 13 wherein the trusted configuration artifact has been signed by a person proposing the change to the configuration and a separate peer review and approval to become committed into the IAC repository.

16. The computer readable storage media defined in claim 9 wherein the method further comprises writing all actions taken with respect to the configuration to an append only log.

17. A system for orchestrating Infrastructure as Code (IAC), the system comprising one or more hardware processors;

a memory comprising instructions which, when executed by the one or more hardware processors, cause the system to:

generate a trusted configuration artifact with a forward immutable continuous integration (CI) implemented as a build pipeline having a plurality of stages with forward immutability between consecutive pipeline stages, with all assets generated in a prior stage of the plurality of stages being immutable to actors in a subsequent stage of the pipeline, wherein each subsequent stage after a first stage of the build pipeline depends on an immutable output of a previous stage in the build pipeline;

detect the trusted configuration artifact has been committed to an infrastructure as code (IAC) repository from a secure pipeline, the trusted configuration artifact including a description of a configuration of a cluster of one or more machines;

access the trusted configuration artifact from the IAC repository; and

automatically deploy the configuration using an orchestrator of the orchestration system to change a state of the cluster, according to an orchestration type associated with the trusted configuration artifact, including determining the orchestration type associated with the orchestrator based on a configuration option associated with the trusted configuration artifact and determining the orchestrator responsible for deploying the determined orchestration type for the configuration associated with the trusted configuration artifact.

18. The system defined in claim 17 wherein the one or more hardware processors are operable to automatically deploy the configuration to change the state of the cluster by compiling code and signaling one or more orchestrators to perform the update to the configuration with the compiled code.

19. The system defined in claim 17 wherein the one or more processors are operable to signal the one or more orchestrators by performing protected writes to the one or more orchestrators to interact with the cluster to update the configuration.

20. The system defined in claim 17 wherein the trusted configuration artifact has been signed by a person proposing the change to the configuration and a separate peer review and approval to become committed into the IAC repository.

Assignments (2)
CHANGE OF NAME Recorded Mar 6, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 075020/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: WALL, JONATHAN
To: STRIPE, INC.
Reel/Frame 057486/0807 →
Cited By (7)
US 12,217,034 US 12,443,572 US 12,498,914 US 12,585,438 US 12,585,462 US 12,632,306 US 12,652,316