IP Library Granted Patent US 11,038,762
Granted Patent B2
US 11,038,762 · App. 16/579,180 · Granted Jun 15, 2021

Arbitrarily grouping computer system resources

Inventors: Cyrus Harvesf (Mountain View, CA); Marco Cavalli (Mountain View, CA)
Assignee: Google LLC
H04L41/0893H04L67/10H04L67/306H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,038,762
App. No.
16/579,180
Granted
Jun 15, 2021
Kind
B2
Abstract

A method for arbitrarily grouping computer system resources includes receiving a resource policy to be applied to a group of resources associated with a user. The resource policy includes a unique user-defined label assigned to each resource of the group of resources. The method also includes identifying the group of resources among a plurality of resources using the user-defined label. Here, the plurality of resources is associated with the user and distributed across a plurality of different computing environments. For each identified resource of the group of resources, the method also includes applying the resource policy to a corresponding identified resource by accessing the respective computing environment where the corresponding identified resource resides.

Claims (31)

1. A method comprising:

assigning, by data processing hardware of a multi-environment manager, a unique user-defined label to each resource of a group of resources associated with a user, the group of resources distributed across at least two different computing environments among a plurality of different computing environments in communication with the data processing hardware, the multi-environment manager forming an abstraction layer that is interoperable with the plurality of different computing environments and configured to:

access resources associated with the plurality of different computing environments;

generate resource policies at the abstraction layer for the resources associated with the plurality of different computing environments; and

deploy, on behalf of the user, resource policies within a respective computing environment of the plurality of different computing environments;

receiving, at the data processing hardware, a respective resource policy to be applied to the group of resources associated with the user, the respective resource policy comprising the unique user-defined label assigned to each resource of the group of resources;

identifying, by the data processing hardware, using the unique user-defined label, the group of resources among a plurality of resources, the plurality of resources associated with the user and distributed across the plurality of different computing environments in communication with the data processing hardware; and

for each identified resource of the group of resources, applying, by the data processing hardware, the respective resource policy to the corresponding identified resource by accessing the respective computing environment where the corresponding identified resource resides.

2. The method of claim 1 , wherein the unique user-defined label comprises a key-value pair.

3. The method of claim 2 , wherein the respective resource policy further comprises a constraint for the key of the key-value pair for the unique user-defined label.

4. The method of claim 2 , wherein the respective resource policy further comprises a constraint for the value of the key-value pair for the unique user-defined label.

5. The method of claim 2 , wherein the respective resource policy comprises a first policy for the key of the key-value pair and a second policy for the value of the key-value pair.

6. The method of claim 1 , wherein the respective resource policy comprises at least one of an access control policy, a firewall policy, a networking policy, or a quota policy.

7. The method of claim 1 , wherein the plurality of different computing environments comprise at least one private computing environment and at least one public computing environment.

8. The method of claim 1 , wherein the data processing hardware is configured to communicate with on-premise computing environments, private computing environments, and public cloud-based computing environments.

9. The method of claim 1 , wherein the plurality of resources comprise at least one of a virtual machine, a database, a key-value store, or a network.

10. A multi-environment system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

assigning, at an abstraction layer that is interoperable with a plurality of different computing environments in communication with the data processing hardware, a unique user-defined label to each resource of a group of resources associated with a user, the group of resources distributed across at least two different computing environments among the plurality of different computing environments in communication with the data processing hardware;

receiving a respective resource policy to be applied to the group of resources associated with the user, the respective resource policy generated at the abstraction layer and comprising the unique user-defined label assigned to each resource of the group of resources;

identifying, at the abstraction layer, using the unique user defined label, the group of resources among a plurality of resources, the plurality of resources associated with the user and distributed across the plurality of different computing environments in communication with the data processing hardware; and

for each identified resource of the group of resources, applying, at the abstraction layer, the respective resource policy to the corresponding identified resource by accessing the respective computing environment where the corresponding identified resource resides.

11. The system of claim 10 , wherein the unique user-defined label comprises a key-value pair.

12. The system of claim 11 , wherein the respective resource policy further comprises a constraint for the key of the key-value pair for the unique user-defined label.

13. The system of claim 11 , wherein the respective resource policy further comprises a constraint for the value of the key-value pair for the unique user-defined label.

14. The system of claim 11 , wherein the respective resource policy comprises a first policy for the key of the key-value pair and a second policy for the value of the key-value pair.

15. The system of claim 10 , wherein the respective resource policy comprises at least one of an access control policy, a firewall policy, a networking policy, or a quota policy.

16. The system of claim 10 , wherein the plurality of different computing environments comprise at least one private computing environment and at least one public computing environment.

17. The system of claim 10 , wherein the data processing hardware is configured to communicate with on-premise computing environments, private computing environments, and public cloud-based computing environments.

18. The system of claim 10 , wherein the plurality of resources comprise at least one of a virtual machine, a database, a key-value store, or a network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2019
From: HARVESF, CYRUS; CAVALLI, MARCO
To: GOOGLE LLC
Reel/Frame 050464/0281 →
Continuity (1)
Related Publication 20210092016A1 · Mar 25, 2021
Cited By (2)
US 12,197,559 US 12,346,689